User guide · Regularly updated

Clash Tutorial

Install · Subscribe · Configure · Advanced · FAQ

From installing a client and importing a subscription to setting up rule-based routing and system-wide TUN mode, this page covers Clash on every platform. It walks through popular clients like Clash Verge Rev and FlClash plus the Mihomo core, for beginners and advanced users alike.

5 minto get up and running
6platforms / cores covered
Step-by-stepclear walkthroughs
Ongoingupdates with new releases
Getting started

Get started with Clash in 5 minutes

Whether you use Windows, macOS, Android or Linux, these 5 steps get you installed, configured and connected.

1

Download a client

Clash Verge Rev for Windows / macOS / Linux, FlClash for Android

2

Install and launch

Run the installer; the Clash icon appears in the tray or notification bar

3

Import your subscription

Open the Profiles page, paste your subscription URL and import it

4

Pick a proxy node

Run a latency test in the proxy panel and pick a node under 200 ms

5

Turn on the system proxy

Enable the System Proxy switch and your browser goes through Clash

Need games or desktop apps to use the proxy too? The system proxy only works for apps that respect proxy settings, such as browsers. To route all traffic through Clash, also enable TUN mode. See Advanced features.
Platform guides

How to install Clash on each platform

Pick your operating system to see the install steps and recommended client.

Clash Verge Rev · Installing on Windows

  1. 1

    Download the installer

    Download the Clash Verge Rev Windows x64 installer (.exe). On Windows on ARM devices with Qualcomm Snapdragon chips, choose the ARM64 build.

  2. 2

    Run the installer

    Double-click the .exe file. If Windows SmartScreen appears, click More info → Run anyway, then follow the setup wizard.

  3. 3

    Install Service Mode (recommended)

    After the first launch, go to Settings → System Settings → Service Mode and click Install (admin rights required). This unlocks system-wide TUN mode.

    Service Mode is a built-in feature of the client. A UAC admin prompt during install is expected; just click Yes.
  4. 4

    Import your subscription URL

    Click Profiles in the sidebar → + in the top right → paste your subscription URL → Import. Your node list appears shortly.

  5. 5

    Pick a node and enable the proxy

    Go to the Proxies page, run a latency test in a proxy group and pick a low-latency node. Then turn on System Proxy.

Subscriptions

How to add a subscription URL in Clash

A subscription URL is an online config address from your provider. Clash uses it to fetch and update all your nodes automatically, so you never have to add them one by one.

  1. 1

    Get your subscription URL

    Log in to your provider's dashboard, find the Clash subscription or subscription URL, and copy the full address starting with https://.

  2. 2

    Open the Profiles page

    In the client's sidebar, open Profiles (in both Clash Verge Rev and FlClash).

  3. 3

    Add a new subscription

    Click + or New, paste the subscription URL, and optionally give it a recognizable name.

  4. 4

    Import and wait for the update

    Click Import or Save. The client downloads the node config and fills in the node list automatically.

  5. 5

    Select the profile and test latency

    Switch to the newly imported profile, run a latency test on all nodes on the Proxies page, pick a low-latency node and turn on the system proxy.

No subscription yet? See our provider recommendations and how to pick one that works with Clash.
Keep it private: Your subscription URL contains account credentials. Don't share it, or others may use up your data.
Update regularly: Providers may change node addresses. If nodes stop working, click Update first to pull the latest config.
Auto-update: In Clash Verge Rev, you can set an update interval (e.g. 24 hours) when editing a subscription, so it stays current on its own.
Import failed? Make sure the URL is complete with no extra spaces. If the subscription server isn't reachable directly, connect through an existing node and try again.
Config file

Clash config file explained

Clash uses YAML config files. Learn a few key fields and you can customize ports, proxy groups and routing rules to fit your needs.

mixed-port

Mixed proxy port

Listens for both HTTP and SOCKS5, usually on 7890. If the port conflicts, change it in the client settings.

proxies

Node list

Defines every proxy node, including SS, VMess, Trojan, VLESS, Hysteria2, TUIC and more. Filled in automatically when you import a subscription.

proxy-groups

Proxy groups

Bundle nodes into groups for manual selection, automatic latency testing, failover, load balancing and other strategies.

rules

Routing rules

Decide whether traffic goes through the proxy, connects directly or gets blocked, based on domain, IP, GeoIP and more. This is how you keep local traffic direct and send the rest through the proxy.

dns

DNS settings

Use different resolvers for local and overseas domains to avoid DNS poisoning and leaks. Especially important in TUN mode.

config.yaml
# Clash / Mihomo config example
mixed-port: 7890
allow-lan: false
mode: rule
log-level: info

dns:
  enable: true
  enhanced-mode: fake-ip
  nameserver:
    - 223.5.5.5          # AliDNS (domestic)
    - https://1.1.1.1/dns-query

proxies:
  - name: HK-01
    type: trojan
    server: example.com
    port: 443
    password: your-password

proxy-groups:
  - name: PROXY
    type: url-test     # Auto-pick lowest latency
    proxies: [HK-01]
    url: https://www.gstatic.com/generate_204
    interval: 300

rules:
  - DOMAIN-SUFFIX,google.com,PROXY
  - DOMAIN-SUFFIX,github.com,PROXY
  - GEOIP,CN,DIRECT      # Mainland China IPs go direct
  - MATCH,PROXY          # Catch-all rule
Advanced setup

Advanced features guide

Master these features to make Clash more flexible and more reliable.

TUN mode (system-wide transparent proxy)

Captures all system traffic through a virtual network adapter. Ideal for games and apps that don't support proxy settings.

  • Clash Verge Rev: install Service Mode first, then enable TUN Mode in settings
  • FlClash (Android): the default VPN mode already proxies everything
  • Pair it with proper DNS settings to avoid DNS leaks
All trafficGamingAdmin rights required

Proxy group strategies (Proxy Groups)

Combine nodes into groups with different strategies for smart switching.

  • select: pick a node manually in the panel
  • url-test: tests periodically and uses the lowest-latency node
  • fallback: switches to a backup when the primary node fails
  • load-balance: spreads connections across multiple nodes
Auto latency testHigh availability

Rule-based routing (local direct · rest via proxy)

Use the rule engine to control exactly where traffic goes, balancing speed and privacy.

  • DOMAIN-SUFFIX: match by domain suffix
  • IP-CIDR: match by IP range
  • GEOIP,CN,DIRECT: mainland China IPs connect directly
  • RULE-SET: reference an external rule set
Local traffic directFine-grained routing

Rule Provider (online rule sets)

Use rule-providers to reference remote rule files that update automatically from upstream, with no manual upkeep.

  • Supports YAML / text / mrs formats with a configurable update interval
  • Popular community rules: Loyalsoldier/clash-rules, ACL4SSR
  • Reference multiple rule sets at once, matched in order
Auto-updateCommunity rules

DNS anti-poisoning setup

The right DNS settings prevent poisoning and leaks, keeping lookups accurate.

  • Resolve domestic domains with a local (domestic) DNS such as 223.5.5.5 (AliDNS) or 119.29.29.29 (DNSPod)
  • Resolve overseas domains with encrypted DNS (DoH / DoT)
  • fake-ip mode speeds up DNS responses
  • Use nameserver-policy to resolve domains by group
Anti DNS poisoningEncrypted DNS

External controller & live monitoring

A built-in RESTful API lets you watch traffic, switch nodes and manage connections in real time from a web dashboard.

  • Set the listen address with external-controller, commonly port 9090
  • Works with web dashboards like metacubexd and Yacd
  • Manage the core on a router or server remotely
  • See which rule each connection matched, handy for debugging
Web dashboardAPI control
FAQ

Clash frequently asked questions

The most common install, config and connection issues, and how to fix them.

My browser still can't load websites after installing. What should I do?

Check the following in order:

  • Make sure the client's System Proxy switch is on
  • Run a latency test in the proxy panel to confirm your selected node works
  • Check whether a browser proxy extension is overriding system settings; if so, set its proxy to 127.0.0.1:7890
  • If the system proxy doesn't help, try enabling TUN mode
Subscription import fails or shows 0 nodes. What now?
  • Subscription expired: log in to your provider's dashboard for a fresh URL
  • Subscription server unreachable: connect via another network or node, then import again
  • Incomplete URL: make sure it starts with https:// and has no extra spaces
  • Incompatible format: check with your provider that they offer a Clash-format subscription
Clash Verge Rev asks me to install "Service Mode". Is that safe?

Service Mode is a system service component bundled with Clash Verge Rev that lets TUN mode run without asking for elevated permissions every time. Being asked for an admin password during install is a normal system authorization step.

If you don't need TUN mode, you can skip it and just use the system proxy.

How do I route games and desktop apps through the proxy?

Clash Verge Rev (Windows / macOS / Linux):

  • Install Service Mode under Settings → System Settings
  • Turn on TUN Mode; from then on, all system traffic goes through Clash

FlClash (Android): Runs as a VPN by default, so it already proxies everything.

How do I fix "port 7890 is already in use"?

Usually an old Clash process didn't exit, or another app is using the port:

  • Fully quit Clash and start it again
  • Change the mixed port to another value (e.g. 7891) in the client settings
  • After changing it, update the proxy port in browser extensions or other apps too
How do I make it start automatically at login?

Clash Verge Rev: Turn on Auto Launch under Settings → System Settings.

FlClash (Android): Allow FlClash to auto-start in system settings, and turn off battery optimization for it so it isn't killed in the background.

How do I troubleshoot high latency or frequent disconnects?
  • Run a latency test on all nodes and switch to a faster one
  • Update your subscription; old nodes may no longer work
  • Peak-hour congestion is common; try nodes in another region
  • On networks with heavy packet loss, UDP-based protocols like Hysteria2 / TUIC usually perform better
  • Check your local network, and test over a wired connection if needed
What's the difference between a subscription URL and a config file?

A subscription URL points to a remote config hosted on a server. The client pulls it periodically, so node changes sync automatically. It's the right choice for most users.

A local config file is a YAML file stored on your device. You can edit its rules and proxy groups yourself, which suits users who want deep customization.

Both use the same format; a subscription URL is essentially a YAML config you can fetch remotely.

Is there a free Clash client for iOS?

Right now, full-featured iOS clients that support Clash configs are essentially all paid apps, such as Shadowrocket, Stash and Quantumult X, each a one-time purchase. See the iOS install notes and the iOS client comparison.

Android shows a security warning when installing the APK. What should I do?

This is the system's standard warning for apps from outside an app store:

  • If Google Play Protect shows a warning, tap Install anyway
  • Or grant permission to your file manager or browser under Settings → Apps → Special app access → Install unknown apps

Only download APKs from official sources such as the project's GitHub Releases.

Ready to get started?

Head to the download center for the latest clients, or compare 14 clients by platform, maintenance status and core.