Diagnose by symptom · Check each item

Clash FAQ and Troubleshooting

Find fixes by stage, from subscription imports and proxy modes to node timeouts and TUN permissions. Change one setting at a time and confirm the result before continuing; this makes the root cause easier to identify.

Recommended order
  1. Confirm the local network
  2. Check the configuration and nodes
  3. Verify the traffic-capture method
  4. Review core logs
Getting Started

Understand the client, configuration, and nodes first

Many problems are not caused by damaged software, but by treating the client, subscription, and nodes as one thing. Understand the role of each component first, and troubleshooting becomes much faster.

What is Clash, and how do the client and core differ?

Clash generally refers to a proxy-tool ecosystem built around rule-based traffic routing. The core reads configuration, establishes proxy connections, applies rules, and handles DNS. The client is a graphical interface layered on top of the core, providing subscription imports, node selection, log viewing, and control toggles. Most users only need a complete client and do not need to download the core separately.

Can I connect immediately after installing a Clash client?

No. The client does not include a ready-to-use proxy service. After the first launch, import a valid subscription URL or local configuration file, select it in the profile list, choose an available node, and enable the system proxy or TUN mode. Without a configuration, the client can only open its settings and cannot establish a usable connection.

When should I use Rule, Global, or Direct mode?

Rule mode decides whether traffic uses the proxy or a direct connection based on domains, IPs, and rule sets, making it suitable for everyday use. Global mode sends most connections through the current proxy node and is useful for checking whether rules are causing access problems. Direct mode bypasses the proxy and is mainly useful for restoring local connectivity or comparison testing; it is not suitable as a permanent mode when a proxy is required.

Are free Clash nodes and the Clash client the same thing?

No. A Clash client reads configuration and forwards traffic, while nodes are provided by separate network services. Public nodes often have unstable availability, route quality, and configuration sources, and may stop working quickly. When a connection fails, first determine whether the client is misconfigured or the subscription or nodes themselves are unavailable.

Can Clash for Windows still be used after maintenance ends?

An existing installation may continue to run, but discontinued maintenance means it will not keep up with system changes, core capabilities, or security fixes. Save or export the current subscription URL, then migrate to a Windows client that is still maintained. You do not need to copy the old application directory; simply import the subscription again and verify the proxy mode, system proxy, and TUN settings.

Installation and Setup

Complete the import, authorization, and traffic capture

Installation is only the first step. Whether the profile is selected, the system architecture matches, and permissions are granted all directly affect whether the client works properly.

How do I import a Clash subscription URL?

Copy the complete subscription URL. In the client, open the Configuration, Subscription, or Profiles page, find the URL import field, paste the URL, and choose Download or Import. A successful import only means the configuration was saved; select it in the profile list to make it active. Then open the proxy page, choose a node, and enable the system proxy or TUN mode as needed.

Why are there no nodes after importing a subscription?

First confirm that you imported a configuration Clash can recognize, rather than a provider webpage, login page, or format intended for another client. Check the download result and core logs. If the file is empty, contains a login page, or fails to parse, copy the subscription URL again and, if necessary, generate a Clash-compatible format in the provider dashboard. Finally, make sure the new profile is selected.

What should I do if Windows blocks the installation?

First verify that the installer came from the project’s release channel linked on this site’s download page, and check that the filename matches your system architecture. If Windows shows a publisher warning, expand the details to review the publisher and file location before deciding whether to run it. Company or school devices may prohibit network tools through administrator policies; follow the device requirements rather than trying to bypass them.

What should I do if macOS says the app cannot be opened or requests permission?

First check whether you downloaded the Apple Silicon or Intel build. Move the app to the Applications folder, then review the block notice under Privacy & Security in System Settings and follow the system’s approval steps. Enabling the system proxy, service mode, or TUN may require further administrator approval on macOS; cancelling authorization prevents those traffic-capture features from being enabled.

Why does TUN mode report insufficient permissions?

TUN creates a virtual network interface and changes routing, so it usually requires administrator privileges or a service component installed in advance. On Windows, try launching once as administrator and installing service mode. On macOS, approve the network extension when prompted. On Linux, confirm that the program can create a TUN device and modify routes. After granting permission, fully quit and restart the client.

Usage Tips

Match the proxy mode to the task

Once a connection is established, focus on choosing the right traffic-capture method and policy group. When something goes wrong, use comparison tests instead of changing many parameters at once.

Should I enable the system proxy and TUN mode at the same time?

In most cases, choose one primary traffic-capture method. The system proxy works well for browsers and apps that follow the operating system proxy settings and is simple to configure. TUN can capture traffic from more apps that ignore system proxy settings, but requires additional permissions. Some clients support both at once, but when troubleshooting, enable only the system proxy first, confirm basic connectivity, and then test TUN separately.

How do I choose a proxy node in Rule mode?

On the proxy page, do not check only the master toggle. Expand the policy groups referenced by the rules, such as node selection, automatic selection, or streaming groups. Assign an available node to the main policy groups before visiting the target site. Some configurations use multiple layers of policy groups; if an upper-level group still points to a broken automatic group, connections may fail even when a lower-level node is selected.

Why do websites remain unreachable when the latency test passes?

A latency test only shows that the test address accepted a connection at that moment; it does not mean every website and protocol will work. Try another node, then temporarily switch to Global mode for comparison. If Global works but Rule mode does not, inspect rule matching and policy groups. If both fail, check DNS, system time, browser secure-connection errors, and the node service status.

How can I update subscriptions automatically without sending requests too often?

Set a reasonable update interval for each subscription. Daily use rarely requires refreshing every few minutes. When routes change infrequently, update every few hours or once a day; use a manual update when you need changes immediately. After updating, check whether the active profile was replaced and whether your selected policy groups reverted to their defaults. Re-select nodes if needed.

How can devices on my local network use Clash as a proxy?

Enable Allow LAN in the client and make sure the listening address is not restricted to the local loopback interface. On a phone or another device connected to the same LAN, set the proxy server to the LAN IP address of the computer running Clash and use the HTTP or mixed port shown by the client. Also check that the system firewall allows the port, and avoid exposing it on public networks.

Which settings should I disable before quitting Clash?

It is best to disable the system proxy and TUN mode before quitting the client normally. This reduces the chance that the operating system retains an old proxy address or route. If the program has already exited unexpectedly and connectivity does not return, disable the manual proxy in the system network settings, reconnect to the network, and check for leftover virtual-adapter routes. Reopen the client only after direct connectivity is restored.

Troubleshooting

From network and nodes to routes and DNS

First confirm that the network works normally without Clash, then check the configuration, nodes, proxy capture, and DNS in order. The first clear error in the logs is usually more useful than repeated reinstalls.

Why can’t I access the internet after enabling the system proxy?

Check in order that the current profile is selected, the policy groups use an available node, the proxy mode is not accidentally set to Direct, and the system proxy port matches the client’s listening port. Then inspect the logs for connection refusals, resolution failures, or timeouts. If ordinary websites are still unreachable after disabling the system proxy, restore the local network first and continue troubleshooting Clash afterward.

What should I check first when every node times out?

First confirm that the local network works without a proxy and that the system clock is accurate. Then update the subscription manually to rule out an old configuration or expired nodes. Temporarily disable other VPNs, proxy apps, and security tools that modify network traffic to avoid port or route conflicts. If every node still times out on different networks, check the subscription service status instead of repeatedly reinstalling the client.

What should I do if a subscription update fails, times out, or returns 404?

A 404 usually means the subscription URL was revoked, copied incompletely, or moved on the server; obtain a new URL from the provider. For timeouts, first confirm that the current network can reach the subscription URL, then try the client’s proxy-update option. If the response is a webpage rather than a configuration file, the login session may have expired or the URL may actually be a management page.

How do I troubleshoot when the browser works but other apps cannot connect?

Browsers usually follow the system proxy, while games, command-line tools, and some store apps may connect directly. First check whether the target program supports manual proxy settings. If it does, enter the HTTP, SOCKS, or mixed port shown by the client. If it does not, use TUN mode to capture its traffic. If only a particular app fails, also check whether the rules incorrectly route its domain to a Direct policy.

What if Windows UWP or Microsoft Store apps bypass the proxy?

Some UWP apps are affected by Windows app-container loopback restrictions and cannot access a local proxy port directly. Use the client’s UWP loopback tool to grant loopback access to apps that genuinely need the proxy, save the changes, and restart the app. Do not select every item indiscriminately. If the client has no such tool, use TUN mode to capture the traffic uniformly.

How can I recover from lost internet or LAN access after enabling TUN?

Disable TUN and quit the client, then confirm that the system routes and DNS have recovered; if necessary, disable and re-enable the current network connection. For another test, turn off the system proxy, enable only TUN, and use the default stack recommended by the client. If LAN devices are unreachable, check that the configuration allows direct LAN access and that private-address rules are not incorrectly sending local traffic through the proxy.

What should I do when Clash has DNS resolution failures or websites load slowly?

Switch nodes first to rule out a route problem, then check the logs for recurring DNS timeouts. Verify that DNS is enabled in the configuration, that the upstream addresses are reachable, and that no other DNS-modifying tools are running on the system. Change one setting at a time. Start by restoring the client’s default DNS settings, then test enhanced resolution or hijacking options individually after connectivity returns.

What should I do if the system still cannot connect after closing Clash?

The system proxy address, virtual-adapter route, or DNS settings may not have been restored. Disable the manual proxy in the operating system’s network settings, then reconnect to the current network. If TUN was enabled, restart the client, disable TUN, and quit normally, or restart the system to clear temporary routes. Once the network works again, check whether the client is configured to launch at startup and capture traffic automatically.