Some internal services are only reachable through a corporate SOCKS5 proxy. On a laptop, you handle that with a PAC file. On iOS you can't: there's no per-app proxy configuration, and most apps ignore the system proxy anyway.
This is how to make those destinations work transparently on any tailnet device — no PAC file, no proxy settings, no per-app configuration — by putting a Tailscale App Connector in front of a sing-box TUN that translates plain TCP into SOCKS5.
Everything below is anonymized. Substitute your own addresses.
The path
Client (Mac / iOS)








