Follow a fixed sequence for the first setup: import the subscription, choose a proxy mode and node, establish the connection, then review the connection log. Only configure what is necessary; consult the configuration reference for complex YAML fields, DNS tuning, and override rules.
If some settings are already complete, jump to the relevant checkpoint. For first-time users, following the steps from the beginning is recommended.
Windows Client Entry Point
Import the subscription on the Profiles page, then choose a policy on the Proxies page. Before connecting, confirm that the client core is running and enable “System Proxy.” Browsers and most applications that follow Windows proxy settings will send traffic through it. Disable the system proxy before exiting Clash to avoid leaving an outdated proxy address in the system settings.
macOS Client Entry Point
Subscription and policy controls are usually available in the main window or the menu bar icon. The first time you enable the system proxy, network extension, or enhanced mode, macOS may request administrator approval. Complete the system prompt, then return to Clash and check the switch. Closing the window alone may not stop the menu bar process.
Android Client Entry Point
After importing the profile and choosing a policy, tap the start button on the main screen. Android will display a permission request for a local VPN connection; approve it and look for the VPN indicator in the status bar. If the connection stops later, check battery optimization, background activity, and notification permissions. These platform settings are covered further on the troubleshooting page.
iOS Client Entry Point
In Clash Plus, add a subscription or profile, choose a policy, and start the connection. The first launch requires iOS to add a VPN configuration. Complete the system verification before establishing the local VPN. Check the system status and Clash logs while connected; after switching networks, return to Clash and recheck the connection status if anything seems wrong.
Linux Client Entry Point
With a graphical client, the sequence is similar to Windows: import the profile, choose a policy, start the core, then configure the system proxy for your desktop environment. Proxy settings vary across distributions and desktop environments. If an application does not read the desktop proxy, configure that application separately or study TUN mode after understanding its routing effects.
BEFORE OPENING
Before You Start
Before you begin, you need two things: an installed Clash graphical client and a valid subscription URL. The client reads the configuration, runs the proxy core, and applies the system proxy; the node provider supplies the subscription URL, which typically contains proxy nodes, policy groups, rules, and update information. They serve different purposes, so a client without profile content will show an empty proxy list.
If Clash is not installed yet, visit the client downloads page and choose the version for your operating system. Launch it normally once after installation. Do not import several unknown or redundant profiles at the same time; mixed policy names, rule sources, and update times make first-time troubleshooting much harder.
When copying a subscription URL, use the entry clearly labeled Clash, Mihomo, or general subscription by your node provider. Do not remove parameters manually or mistake a web account URL for a subscription URL. A valid subscription is usually a complete URL beginning with https://, often followed by a long path and query parameters. Copy it in full—messaging apps may truncate it or add spaces, causing the download to fail.
01SUBSCRIPTION
Import a Subscription Configuration
Find the Profiles or Subscription Page
After opening Clash, look for “Profiles,” “Subscriptions,” or a similarly named page. This section stores configuration sources; it is not where you choose nodes. Desktop clients usually provide a separate entry in the left navigation, while mobile clients may place Profiles at the top of the main screen or in a side menu. You should find options such as importing from a URL, creating a profile, updating it, or scanning a QR code.
Choose Import from URL and paste the complete subscription address into the input field. Some clients also ask for a profile name; use the provider name or purpose, such as “Daily Rules,” rather than putting the subscription URL in the name field. Check for spaces at either end, then click Download, Import, Save, or Confirm and wait for the request to finish.
Confirm That the Profile Downloaded
After a successful import, a new entry with a recognizable name should appear in the profile list. Select it as the current profile, then open the Proxies or Policies page. You should normally see several policy groups containing node names, automatic selection, direct connection, or other sub-policies. A profile appearing in the list does not mean it is active; confirm that the selected indicator is on the newly imported profile.
Some clients load an imported profile immediately; others require another click on “Use,” “Enable,” or a radio button. When loading finishes, the log often records profile parsing, proxy port startup, or rule loading. If Clash reports a YAML parse error, unsupported fields, or an empty profile, do not start the connection. Check the subscription type with the provider, then copy and import it again.
Locate the Source of an Update Error
For a network request failure, first confirm that your regular connection can open other websites, then check whether the subscription has expired. You can paste the URL into a browser to test it, but do not save it on a public device or post the complete address publicly. If the browser also fails, the issue is usually the subscription or current network. If the browser retrieves the content but Clash fails, check network permissions, system time, and existing proxy settings.
If the node list is empty after import, run one manual update and select the profile again. If it is still empty, read the exact error instead of repeatedly deleting and reinstalling Clash. An expired subscription, an unexpected response format, and a local core that cannot parse the profile produce different messages; handling them separately is more effective. See Troubleshooting for more error mappings.
02ROUTING MODE
Choose a Proxy Mode and Policy
Use Rule Mode for the First Connection
Open Settings, General, or Mode and find the proxy mode option. Common modes include Rule, Global, and Direct. For a first setup, choose “Rule” mode: Clash evaluates traffic against the configured rules, sends proxied connections to policy groups, and keeps local services or specified domains direct. This verifies the subscription while preserving the provider’s intended routing logic.
Global mode generally sends most traffic through one proxy policy. It can help determine briefly whether a particular node can connect, but it should not be the only troubleshooting method when its broader effects are unclear. Direct mode bypasses the proxy and is useful for comparing behavior with the proxy disabled. A mode describes how rules handle traffic; it does not enable the system proxy. You still need to complete the connection step.
Choose an Egress in the Main Policy Group
Open “Proxies,” “Proxy,” or the policy page and find the group responsible for most external traffic. It may be named “Node Selection,” “Proxy,” or something custom from the provider. Expand it to choose a node, or select a sub-group such as “Auto,” “Failover,” or “Load Balance.” For the first connection, choose a clearly available node or a configured automatic group; there is no need to edit every policy group.
If the client offers latency testing, run one basic test. Latency only shows whether the test target responded at that moment; it does not guarantee access to every website or prove node quality by itself. If one node times out, test another. If all nodes time out, return to the first step, check the subscription update time, and verify the local network, firewall, and system clock.
A profile may contain policy groups for different purposes, such as streaming, messaging, downloads, or fallback rules. For the initial setup, confirm only that the main proxy group has a selection; leave the other groups at their subscription defaults. Changing too many policies at once makes verification inconclusive because a failure could come from the node, rules, or manual selections.
Keep DNS and TUN at Their Defaults
Some clients expose DNS, TUN, mixed port, bypass list, and configuration override options. These address more complex application compatibility, full traffic interception, and DNS resolution issues; they are not required for a first connection. Keep the provider’s defaults until basic proxy verification is complete, then decide whether changes are necessary.
TUN mode in particular creates a virtual network adapter or changes routing. It may require additional permissions and conflict with other VPNs, virtual machines, or security software. If the standard system proxy works for your browser and common apps, do not enable TUN for this guide. For applications that ignore system proxy settings, read the related fields and concepts in the configuration reference.
03CONNECT
Establish the Proxy Connection
Desktop: Start the Core and Enable the System Proxy
Windows, macOS, and common Linux graphical clients usually expose two related states: whether the proxy core is running and whether the system proxy is enabled. First check the main screen or status bar to confirm that the core has started without ongoing profile errors. Then enable “System Proxy,” “Set as system proxy,” or a similarly named switch. Once active, Clash writes the local proxy address to the operating system, allowing browsers and most system-proxy-aware apps to send requests through Clash.
On Windows, Clash may continue running in the system tray; on macOS, the menu bar process may remain active after the main window is closed. Do not terminate the process during testing, or the system proxy and listening port may fall out of sync. Before exiting, disable the system proxy first, then use the client’s Quit command to avoid leaving the operating system pointed at a stopped local port.
When enabling these features for the first time on macOS, the system may request network extension, accessibility, or administrator permissions. Follow the system prompts, then return to Clash and enable the connection again. If permission was previously denied, allow it again in System Settings instead of repeatedly clicking the same switch. See Troubleshooting for platform-specific permission paths.
Mobile: Approve the Local VPN Connection
Android and iOS clients generally use the system’s local VPN interface to handle traffic. Select the current profile and policy, then tap the start button on the main screen. On the first connection, the system will request permission to add a VPN configuration or connect; approve it so Clash can create the connection. When connected, the system status area usually shows a VPN indicator and the main screen changes from stopped to running.
If Android stops the connection soon after launch, first check whether background activity is restricted. Add Clash to the allowed background activity or battery optimization exceptions and keep the required notification permission enabled to reduce termination after the screen turns off. Menu names vary by manufacturer; look under Battery, App launch, or Background activity in device settings.
iOS rebuilds its network path when switching between Wi-Fi and cellular data. If a page temporarily fails to load, return to Clash to check whether the connection is still enabled, then stop and reconnect if needed. Do not run another app that uses the system VPN interface at the same time, as the system generally allows only one primary VPN configuration to handle current traffic.
Use One App for the First Test
After the connection is established, test with one familiar browser instead of immediately launching downloads, games, virtual machines, and other VPNs. A single app makes connection logs easier to read and reduces background traffic. Open a page that normally works to confirm basic connectivity, then visit a page expected to match a proxy rule and proceed to the fourth step to check the result.
If no pages load after enabling the system proxy, disable it to restore the regular connection and inspect the Clash logs. Common causes include a stopped core, an unreachable node, a port conflict, or security software blocking the local listener. Do not switch to TUN mode just to bypass the issue; get the standard system-proxy path working first.
04VERIFY
Verify That the Proxy Works
Check Connection Logs, Not Just the Switch Color
A “Connected” status only shows that the core or local VPN has started; it does not prove that the target request used the proxy. Open “Connections,” “Connection,” or the log page in Clash, then refresh the test page in your browser. The list should show a new domain or IP, the matched rule, the policy group, and the final egress. A growing list indicates that the app’s traffic is reaching Clash.
Focus on the connection for the test domain rather than letting background requests obscure it. In Rule mode, some connections showing DIRECT are normal because the profile may keep local services, LAN addresses, or specified sites direct. Confirm that the target expected to use the proxy matched a proxy policy and ultimately used the node or policy group selected in step two.
Run an On/Off Comparison Test
Keep the test page unchanged. Refresh it with the connection enabled and note the result; then disable the system proxy or mobile connection and refresh the same page again. The two results should match the rule’s expected behavior. Re-enable the connection afterward and check the connection list again. This helps rule out browser cache, reused connections, and pages that happened to load successfully.
Browsers may reuse an existing long-lived connection, so the page may not change immediately after the proxy is disabled. Close and reopen the tab, or wait for the old connection to end, then inspect new connection records. Do not judge proxy status solely by old content remaining visible; dynamic requests, images, and new connections are better indicators of the current path.
Choose the Next Troubleshooting Direction
If no browser request appears in the connection list, traffic has not reached Clash. On desktop, check that the system proxy is truly enabled and that the browser is not using separate proxy settings; on mobile, check the VPN indicator and system authorization. If a connection appears but ends up as DIRECT, inspect Rule mode, the policy group, and the rule matched by the domain.
If the log shows the expected proxy policy but requests still time out, test another node and check for connection refusals, handshake failures, or DNS messages. If only some nodes fail, suspect node reachability first. If every node and target fails, check the subscription, system time, network restrictions, firewall, and DNS.
If the browser works but one specific app does not, that app may ignore the system proxy or use a separate network stack. This does not mean the basic setup failed. Check the app’s own proxy settings first; if all-traffic interception is necessary, evaluate TUN mode and read the configuration reference for routing, DNS, and permission implications.
AFTER CONNECTION
After Setup: Everyday Settings
Once the basic connection is stable, add automatic updates, launch at startup, or advanced routing one item at a time. Repeat the verification after each change.
Routine Maintenance
Recheck Policies After a Subscription Update
An update may add, remove, or rename nodes and may change the policy-group structure. After updating, return to the Proxies page and confirm that the main policy still has a valid selection. If the previously selected node was removed, choose a new egress.
Enable as Needed
Configure Launch at Startup and the System Proxy
After confirming that Clash starts and exits reliably, consider enabling launch at startup. Keep “Launch client” and “Automatically enable system proxy” as separate options so the system does not apply proxy settings automatically when the profile is invalid.
Advanced Configuration
Handle DNS, TUN, and Overrides Later
Adjust these options only when an app ignores the system proxy, DNS resolution fails, or custom rules are required. Preserve a working profile before making changes, and check the logs and connection records after each change.
Need to Identify a Specific Error
Find the relevant fix by symptom, including subscriptions, nodes, system proxy settings, VPN permissions, and DNS.