Run Only One Client
Quit other proxy clients, VPNs, and network debugging tools to reduce conflicts between system proxy ports and virtual network adapters.
Quickstart · About 10 minutes
This workflow applies to common Clash clients on macOS, Windows, Android, and iOS. The order is always the same: import the profile, choose Rule mode, establish the system connection, and verify real requests. Labels may differ, but the functions generally correspond.
This page covers only the essential actions after opening the client for the first time. Once the four steps are complete, browsers and applications that follow system network settings can access the network according to the profile's rules. Port fields, DNS modes, strategy group types, rule syntax, and profile merging are covered later in the Configuration Field Reference; you do not need to master them during the first connection.
Before you begin, install a client suitable for your operating system and obtain a subscription URL that supports Clash or Mihomo from your service provider. A subscription URL is essentially a configuration entry point and usually contains nodes, strategy groups, rules, and DNS settings. This guide does not require writing YAML by hand. If your service provides a link in another format, select a Clash-compatible format in the provider's dashboard before importing it into the client.
Before · Preflight
First, confirm that the client starts normally and that the device can access the service page associated with the subscription URL. The first time you run a downloaded app on macOS, the system may ask you to confirm its source; Windows may request network access; Android and iOS request permission to create a VPN connection when you connect. Complete these normal system prompts first, and do not enable multiple network tools at once. Two similar clients controlling the system proxy or VPN interface can make later verification difficult to interpret.
Next, check that the device date, time, and time zone are correct. Subscription downloads and proxy protocols commonly rely on TLS, and a significant clock error can appear as failed profile updates, certificate time mismatches, or every node being unavailable. Let the system set the time automatically, then close any other proxy clients and keep only the application you are configuring running.
Finally, prepare the subscription URL. A complete address usually starts with https:// and is generated from your service provider's account page. Treat it as account configuration data; do not paste it into public chats, screenshots, or public support posts. If the URL has been exposed, reset it on the original service page before importing it. After these checks, move to the first step so installation, subscription, and connection issues do not get mixed together.
Quit other proxy clients, VPNs, and network debugging tools to reduce conflicts between system proxy ports and virtual network adapters.
Copy the complete URL from your service provider's dashboard. Do not mistake a webpage URL or account login URL for the subscription URL.
Step 01 · Profiles
After opening the client, find its profile management page. macOS menu bar clients such as ClashX Meta typically require clicking the menu bar icon and opening “Configuration” or “Managed Configuration.” Desktop clients such as Clash Verge Rev and Clash Plus generally provide “Subscriptions” or Profiles in the sidebar. Android clients often show the current profile name on the home screen; tap that area to open the profile list. You should find entries such as local profiles, remote subscriptions, or add-profile options.
Choose “Import from URL,” “New Subscription,” or an equivalent action, then paste the complete subscription URL into the URL field. Use a short, recognizable name, such as the service name plus its purpose, but do not put node passwords or subscription parameters in the name. Leave the automatic update interval at the client's default for now; the priority during first-time setup is confirming that the profile downloads successfully. After you click Save, Import, or Update, the client requests the profile from the subscription URL and adds a new entry to the list.
A successful import does not mean the profile is active. Return to the profile list, find the newly created entry, and click “Enable,” “Set as Current,” or the card itself to select it. The active state usually appears as a check mark, an accent-colored border, or a changed current-profile name on the home screen. If the list contains a profile but none is selected, the proxy group page may be empty or may still use the client's built-in example profile.
If clicking Import immediately reports an invalid URL format, check whether spaces, line breaks, or explanatory text were copied around the URL; the field should contain one complete address only. If the request times out after waiting, sign in to the service provider's website to confirm the account and subscription status, then copy the URL again. If the download succeeds but the client reports a YAML parsing error, the response is usually not a Clash configuration the client recognizes, or the profile contains indentation or compatibility issues.
When parsing fails, do not edit large sections of YAML during first-time setup. Return to the provider's dashboard, switch to a Clash, Mihomo, or explicitly supported client format, delete the failed entry, and import it again. If the cause remains unclear, see Troubleshooting for subscription and profile issues; to understand the profile structure, consult the Configuration File Field Reference.
Step 02 · Rule
Once the configuration is enabled, open the “Mode,” “Proxy Mode,” or Mode settings. Common options include Rule, Global, and Direct, typically shown in English as Rule, Global, and Direct. For an initial setup, choose Rule mode. It reads the rules in the configuration file and uses conditions such as domains, IP addresses, and application types to decide whether each request should connect directly, go through a proxy, or be handled by another policy. This is also the operating mode expected by most subscription configurations.
Global mode sends most proxyable requests through one proxy strategy. It is useful for briefly testing whether a node works, but it is not a good default when you do not understand the rules. Direct mode bypasses the proxy and is useful for pausing proxying or checking whether the client affects the local network. These modes do not change the nodes themselves; they change how requests enter the strategy groups. Keep Rule mode enabled during testing so the connection results remain clear.
After choosing the mode, open the “Proxies,” “Strategy Groups,” or Proxies page. This is usually more than a simple node list: it contains multiple strategy groups, some for manual node selection, some for automatic testing, and others for streaming media, messaging, or direct connections. Find the main manual-selection group defined by the profile. It may be called “Node Selection,” “Proxy,” “PROXY,” or a custom provider name, then choose an available node in that group.
If the client provides a latency test, use it to check whether a node can complete the test request. The number reflects one test address at one point in time; it is not the same as webpage loading speed or sustained connection quality. During initial setup, do not compare every number repeatedly. Choose a node that returns a result and matches your location requirements. If every node times out, update the subscription once and check the local network and system time before moving to the connection step.
Rule
Routes traffic directly or through a proxy according to the profile's rules; this is the mode used in this guide.
Global
Primarily for temporarily testing a single node; it does not use the normal routing results.
Direct
Sends requests straight to their destinations and can be used to compare the state of the local network.
After clicking a node, check whether the strategy group header shows the new node name. Some clients save automatically when you leave the page, while others require another confirmation click. If the group uses automatic selection, the interface may show only the automatic strategy name rather than a specific node; you can leave that default in place. Do not change multiple strategy groups during first-time setup, or it will be difficult to identify which choice caused a later problem.
The relationship between Rule mode, strategy groups, and nodes can be summarized as follows: rules first send a request to a strategy group, and the strategy group then selects the actual node or direct action. This is the minimum configuration; just make sure Rule mode is enabled and the main strategy group has a clear selection. After the connection works, read the Configuration Field Reference to learn about strategy group types such as select, url-test, and fallback. They do not affect the current workflow.
Step 03 · System Proxy
On desktop platforms, find the “System Proxy,” “Set as System Proxy,” or System Proxy switch. Once enabled, the client points the operating system's HTTP and HTTPS proxy settings to a listening port on the local machine. macOS menu bar clients usually offer the switch directly in their menus; Windows clients commonly show it on the home or settings page. When enabled, the button state changes and the system network settings show a proxy pointing to a local address.
Android and iOS connect differently. On mobile, tap the start button on the home screen; the system then asks for permission to establish a VPN connection. After approval, a VPN indicator appears in the status bar and the client home screen shows its running state. This VPN interface sends device traffic to the client for processing; it does not change the Rule mode or strategy group selected earlier. For the first authorization, follow the system dialog—no manual server address is required.
After enabling the connection, wait a few seconds for the client to start listening on its ports, initialize DNS, and load the rules. Do not click the switch repeatedly or change profiles immediately. If a desktop client cannot set the system proxy, check that it has the required permissions and that another network tool is not continuously rewriting system settings. If a port is already in use, another client is usually still running in the background, or an earlier process did not exit cleanly. Stop the conflicting program and restart the current client.
Browsers and most desktop applications that follow system proxy settings send requests through this entry point. Keep the client process running after enabling it; quitting the application stops the local proxy port from listening.
On mobile, confirm both that the client is running and that the system shows a VPN indicator. Selecting a node without starting the VPN does not send application traffic through the client.
The system proxy covers browsers and applications that follow system network settings, but some command-line tools, games, and applications that create their own connections may ignore it. If the client supports TUN, a virtual network interface can handle a broader range of traffic. TUN also involves system permissions, routing, and DNS, so avoid repeatedly adjusting it together with the system proxy during first-time setup. Verify the browser with the system proxy first, then decide whether to enable TUN based on the applications you actually need to cover.
If your goal is everyday web browsing, you normally do not need to change ports here. mixed-port, port, and socks-port in the profile are local listening endpoints, and the client automatically points system settings to the correct port. Check these fields only when another application requires manual proxy settings or there is a clear port conflict. For detailed explanations of ports and TUN routing, see the Configuration Field Reference; common permission and conflict fixes are listed in Troubleshooting.
Step 04 · Connections
After connecting, do not judge the result by the switch color alone. Open a new browser tab and visit a site that normally works directly to confirm the local network is still healthy, then visit a target page that requires a proxy. If both types of pages open, the system connection, rule routing, and node path are working together. If only direct pages work, the issue is usually the proxy node, strategy group selection, or proxy rules. If no pages open, check the system proxy port, client status, and DNS first.
Then return to the client, open the “Connections,” “Sessions,” “Logs,” or Connections page, and refresh the browser again. Under normal conditions, new request records appear with the destination domain, matched rule, strategy group, or actual node name. Find the domain you just visited and confirm that it matched the expected strategy. A request that requires a proxy should enter the main proxy group, while local services or commonly direct sites may show DIRECT. This is more useful for confirming that the rules work than simply checking the exit IP address.
If a browser page opens but the connection list shows no new records, the browser may have its own proxy settings, another VPN may be active, or the system proxy may not actually point to the current client. Disable separate proxy extensions in the browser, recheck the system proxy switch, then fully quit and reopen the browser. If a connection record exists but matched an unexpected strategy, system interception is working and you should investigate the rules or strategy groups rather than reinstalling the client.
Check the Page Results
Test a direct page and a page that requires a proxy separately.
Check the Connection Records
Refresh the page and confirm that the client shows the corresponding domain.
Check the Rule Match
Verify the strategy group and actual node handling the request.
When the client shows connected but webpages do not open, check one variable at a time in this order. First, confirm that the current profile is still selected and that its update did not fail. Second, return to the main strategy group and switch to a node that completes a test. Third, turn the system proxy or mobile VPN off and on to rebuild the connection. Fourth, check whether the target domain appears in the connection records. Fifth, inspect the logs for DNS errors, connection timeouts, or port conflicts.
If switching nodes fixes the issue, the profile and system interception are basically working and the original node is currently unavailable. If the connection list contains no requests at all, focus on the system proxy, VPN authorization, and other network tools. If the request reaches the client but domain resolution fails, investigate DNS next. DNS issues should not be handled by randomly changing many options, because fake-ip, redir-host, system DNS, and TUN work together in specific ways. Use Troubleshooting based on the observed log behavior, then consult the DNS and Configuration Fields chapter when you need to verify individual fields.
After · Daily Use
After the first connection is complete, daily use usually comes down to three actions: start the client, confirm that the system proxy or mobile VPN is enabled, and update the subscription when needed. An update retrieves nodes and rules from the original URL; you normally do not need to delete and re-import the old profile. After updating, check that the current profile is still selected and that the main strategy group uses the intended choice.
After changing networks—for example, switching from a home network to an office network or mobile hotspot—the client may need to reconnect. If the system proxy still appears enabled but no traffic passes, turn the connection off and on once. On mobile, restart the VPN. If the same issue appears after waking the device from sleep, rebuild the connection before changing the subscription or DNS.
Rules, strategy group types, DNS, ports, overrides, and profile merging are advanced maintenance topics. To understand individual fields, read the Clash Configuration File Reference by chapter. For failed subscription updates, port conflicts, a non-working system proxy, or a connected client with no access, use Troubleshooting to identify the issue by its symptoms. To choose a client for another platform or download an installer again, return to the Installers page.
The first connection is complete. For follow-up issues, open the field reference or troubleshooting guide relevant to the problem instead of changing every advanced option at once.