About 10 minutes to complete

Clash Subscription Import and Connection Guide

Follow this order: “Import subscription → Choose a proxy mode → Establish a connection → Verify the result.” Once complete, the client can process network requests according to the rules in the configuration file.

Before You Begin

This guide assumes that a working Clash GUI client is already installed and that you have an importable subscription link or YAML configuration file. If the client is not installed yet, visit the client download page and choose the version for your operating system. Windows and macOS users can generally use a GUI client; Android and iOS require a mobile client; Linux desktops can use a GUI client, while servers are better suited to a standalone core deployment.

For the first setup, temporarily close other software that manages the system proxy, VPN, or network filtering on the device. Multiple programs changing the system proxy, routing table, or DNS can cause intermittent access, a client that says it is connected while requests bypass Clash, or continued network problems after the client closes. You only need to exit the relevant programs for now; there is no need to change advanced browser network settings or enter a proxy server address manually.

Keep the subscription link intact. When copying it, do not omit the opening https://, and do not include punctuation, parentheses, or spaces added by a chat app. Subscription URLs often contain access credentials, so treat them like account information and never publish them in a public page, screenshot, or log. If you received a local YAML file, choose “Import from file” in the import step below; the rest of the process is largely the same.

This page covers only the steps required for a first connection. After connecting successfully, read the protocol and core reference for protocol types, core families, resource usage, and compatibility between subscription formats. Establish one verifiable working path first, then adjust advanced features so troubleshooting stays orderly.

Step 1: Import the Subscription

Find the Configuration or Subscription Page

After opening the client, look for “Subscription,” “Configuration,” “Profiles,” or “Configuration Files.” Desktop clients usually place it in the left navigation, while mobile clients typically place it on the home or settings page. You should find a configuration list, an update button, and an option to add a configuration from a URL or local file. If the page is empty, that is normal: the client has not loaded a usable configuration yet.

Choose “Import from URL,” “New Subscription,” or a similarly named button. Paste the complete subscription link into the address field. Some clients also ask for a configuration name; use a short, recognizable name such as “Daily Configuration.” The name only identifies the item in the local list and does not change the subscription content. Check that the address contains no extra spaces, then click Import, Save, or Download and wait for the request to finish.

Confirm That the Configuration Loaded

After a successful import, a new item appears in the configuration list. Do not rely only on a brief “Import successful” message; open the configuration and confirm that its contents were parsed. Typical signs of a valid result include a configuration name and update time, proxy groups such as “Auto Select” or “Node Select,” and rule entries on the rules page. Proxy-group names vary by subscription, so there is no need to look for a specific name; the important point is that the client is no longer completely blank.

If the client supports multiple configurations, click Enable, Select, or Set as Current beside the new one. Importing only saves the file in the client; setting it as current makes the core read its ports, DNS, proxy groups, and rules. After switching, some clients reload the core automatically, while others show a “Reload” button. Follow the prompt and reload once if needed.

Once the configuration loads, do not immediately enable several network switches. First open the proxy page, choose the operating mode and proxy group, and make sure requests are sent according to the intended policy. If access fails in the next step, this keeps the issue focused on mode selection instead of mixing subscription, system proxy, and TUN troubleshooting.

Step 2: Choose a Proxy Mode

Start with Rule Mode

Open the “Proxy,” “Proxies,” or “Mode” page and find the Rule, Global, and Direct options. For first-time use, choose “Rule” mode. Rule mode matches the rules in the configuration file from top to bottom, deciding whether each request connects directly, uses a proxy group, or is rejected based on domains, IPs, rule sets, and other conditions. Everyday websites, software updates, and local network services can be handled separately instead of forcing all traffic through one path.

Global mode sends most requests to the selected proxy group. It is useful for briefly checking whether a problem is caused by rule matching, but it is not recommended as a permanent setting for every situation. Direct mode normally bypasses the proxy and can be used to restore ordinary network access temporarily or run a comparison test. The mode controls traffic decisions, not whether the connection is enabled; after choosing a mode, you still need to enable the system proxy or TUN in the next step.

Check the Current Proxy-Group Selection

Rule mode usually includes multiple proxy groups. Open the main proxy group and choose a strategy available in the subscription. If the configuration provides “Auto Select,” “Failover,” or a similar option, start with the subscription's default choice. If manual selection is required, choose an entry that is clearly available. Do not change every proxy group at once. Identify the group handling the main requests, then leave the others at their configured defaults to reduce variables during initial setup.

Proxy-group names and hierarchies are defined by the configuration provider, so users may see very different pages. Some configurations use “Node Select” as the main entry and reference other strategy groups beneath it; others divide groups by purpose. You can continue as long as the current group is not empty and one strategy is selected. Rule syntax, matching order, and nested proxy groups are advanced topics covered in the overall relationship explained on the protocol reference page.

After choosing the mode and proxy group, the client knows how to process requests, but the operating system has not yet handed application traffic to it. Next, choose the system proxy or TUN according to the platform. For a first connection, start with the less invasive option: use the system proxy on desktop, and establish a system VPN connection on mobile.

Step 3: Establish a Connection

Windows and macOS: Enable the System Proxy First

Return to the client's overview or settings page and turn on the “System Proxy” switch. The client will point the operating system's proxy address to its local listening port, allowing browsers and apps that support system proxy settings to send requests through Clash. Keep the client running afterward; closing the main window usually minimizes it to the system tray or menu bar. Check the tray icon, menu-bar icon, or Task Manager to confirm that it is still running.

The system proxy is ideal for the first verification because it does not take over the device's entire routing path. Modern browsers and many desktop apps read system proxy settings, but some games, command-line programs, and applications with their own network stack may ignore them. If the browser works but a specific app creates no connection records, the configuration is not necessarily broken; first check whether that app supports the system proxy.

Android and iOS: Approve the System Connection Request

Mobile clients usually forward traffic through the system VPN interface. Tap the Connect button on the home screen, then approve the system authorization dialog for creating a VPN connection. A VPN indicator appears in the status bar, and the client home screen shows a connected state. This first authorization is an operating-system security step; if it is denied, the client cannot receive requests from other apps even if the configuration was imported.

Mobile operating systems may pause the client during battery saving, background restrictions, or network changes. During the first test, keep the client in the foreground. After confirming that the browser works, allow the necessary background activity in the device settings. If the connection drops when switching between Wi-Fi and mobile data, return to the client and check the system connection status instead of immediately deleting and re-importing the configuration.

When to Use TUN Mode

Consider TUN mode if a desktop application clearly ignores the system proxy or if you need to handle more types of network traffic consistently. TUN creates a virtual network interface and may require administrator privileges, a helper service, or driver support. Before enabling it, close other VPNs and similar network tools, follow the client's instructions to install the service, then recheck the active configuration and Rule mode.

For the first setup, do not enable the system proxy, TUN, and several experimental DNS options at the same time. Some clients can coordinate these settings, but troubleshooting becomes difficult when something fails. A safer order is to verify the browser with the system proxy first, then enable TUN separately and test again only when broader application coverage is needed. For TUN permissions, service-mode failures, DNS resolution issues, and UWP loopback, see the platform-specific guidance in the Frequently Asked Questions page.

Step 4: Verify That It Works

Test with a New Request

For verification, open a new browser tab and visit an ordinary webpage that has not been opened before. A new tab reduces the effect of browser cache, existing connections, and old DNS results. A page loading is only the first check; return to the client and open the “Connections” or “Logs” page to confirm that the domain request actually appears.

After finding the domain in the connection log, check three details: which rule matched, which proxy group handled the request, and whether the final route was direct or proxied. Different websites producing different results in Rule mode is normal. If the request appears and the policy matches the configuration's expectations, the path from the operating system to the client core is working.

Identify Where the Failure Occurs

If the browser cannot connect and the client's connection page shows no new record, check the system proxy, mobile VPN authorization, TUN status, and whether the client is still running. This usually means the request has not reached Clash. On desktop, turn the system proxy off and on again so the client rewrites the operating-system settings. On mobile, disconnect and reconnect, then confirm that the system status bar shows the connection indicator.

If the connection page shows the request but it was sent direct when a proxy was expected, check the matched rule and current mode. Briefly switch to Global mode for one comparison test, then switch back to Rule mode. If Global works while Rule does not, inspect the rule assignment instead of repeatedly reinstalling the client.

If the request was assigned to a proxy group but still fails, check whether the selected strategy in that group is available, then try another clearly available option from the same group. Change one selection at a time and send the request again. If no option in the configuration works, update the subscription or contact the configuration provider about service status; the client cannot repair upstream configuration content.

If webpages work but a command-line tool, store app, or game creates no connection record, first check whether the program reads the system proxy. Some Windows UWP apps may require loopback access, and command-line tools may need proxy environment variables set separately; use TUN when broader coverage is required. The relevant procedures and permission issues are collected under Troubleshooting; this guide does not cover system-level networking in detail.

Clean Up After Testing

If Global mode was used temporarily for troubleshooting, switch back to Rule mode after verification. If multiple connection methods were enabled for comparison, keep only the one you actually need so the traffic path is clear next time. Before closing the client, disable the system proxy or use the client's normal exit function so system settings can be restored. If the network misbehaves after force-quitting the process, reopen the client and toggle the system proxy once to restore it.

Everyday Use After Setup

After the first connection, daily use requires only a few checks. Start the client, confirm that the current configuration is still selected, enable the system proxy or mobile connection as needed, and keep Rule mode active. Client upgrades usually do not require re-importing the subscription, but after an upgrade you should still check the configuration, proxy groups, and connection switches, especially after a major version change or core replacement.

Subscription contents can change when the provider updates them, so refresh the configuration regularly from its page. Keep the currently working configuration before updating; after the update, check that the proxy groups still have selections and reload the configuration. If the update fails, do not delete the old configuration immediately. It may still work, and keeping it makes it easier to compare the old and new contents and determine whether the problem is the link or the client.

Before changing rules, DNS, or proxy groups, make a copy of the configuration as a local version. Subscription updates may overwrite provider-managed content, and whether local changes are preserved depends on the client's merge behavior. For long-term custom rule maintenance, first understand rule order, proxy-group references, and DNS modes, then decide whether to use an override, script, or separate configuration. Continue with the protocol and core technical reference for the related concepts.