TUTORIAL

Clash Setup Tutorial: From Subscription Import to Connection Verification

The full process breaks down into four steps: import the subscription link, choose a proxy mode and node, turn on the connection, and verify it's working. Follow them in order to finish your first-time setup — each step notes the interface differences across clients. If you haven't installed a client yet, head to the download page for your platform's installer first.

Platform and client differences: The menu names in this article follow Clash Verge on Windows / macOS / Linux. In Mihomo Party, "Subscription" corresponds to "Profile Management"; in FlClash, it maps to "Profiles"; on Android, Clash Meta for Android (CMFA) uses the "add new profile" entry on the "Profiles" page. The exact location of each feature varies slightly between clients, but the core flow — "import subscription → pick a node → enable proxy → verify" — is identical throughout. If a name doesn't match, look for the equivalent entry by meaning.

Get the subscription link

The subscription link is provided by your proxy service, usually found under "Subscription" or "My Services" in the provider's user panel — it's a long URL starting with https://. Click "Copy subscription link" in the panel to copy it to your clipboard. Treat this link like an account credential: never share it with others or paste it anywhere public. For more on how subscription links are structured and refreshed, see the "Subscriptions and profiles" entries in the glossary.

Import it into the client

Open Clash Verge and click "Subscriptions" in the left sidebar to reach the profile management page. There's an input field at the top of the page — paste the link you just copied, then click the "Import" button on the right. The client immediately requests that link and downloads the profile; once successful, a profile card appears below showing the profile name, remaining data, and expiration date (whether these show up depends on whether the provider supplies that information).

In Mihomo Party, the entry point is the "New" button on the "Profile Management" page; in FlClash, click the plus icon in the bottom right of the "Profiles" page and choose "Import from URL"; in CMFA, tap the plus icon on the "Profiles" page, choose "Import from URL," paste the link, and save. All four share the same pattern: paste the link, confirm the import, and wait for the new profile to appear in the list.

Activate the profile

Importing doesn't mean it's active yet. Click the profile card to select it (in Clash Verge, a selected card gets a highlighted outline) — only then is the profile actually loaded into the core. If you see a network error or timeout during import, it's usually because the subscription link itself requires a proxy to reach, or the link has expired; see the troubleshooting section of the FAQ for fixes. Once the card is confirmed selected, move on to choosing a node.

Next: choose a proxy mode and node ↓

Confirm the running mode

Click "Proxies" in the left sidebar to open the proxy page. There's a mode switcher at the top: Rule, Global, Direct. Keep the default Rule mode for everyday use — it routes each connection to proxy or direct based on the rules in the profile, delivering the best balance of data savings and performance. Global mode sends all traffic through the proxy and should only be used when debugging rules or when you temporarily need full proxying; Direct mode bypasses the proxy entirely. For a detailed comparison of the three modes and when to switch, read the blog post "Clash Rule Mode vs. Global Mode: Differences and When to Switch."

Test latency and select a node

Below the mode switcher is the list of proxy groups. Expand the main group — usually named something like "Proxy Selector" or "PROXY" — to see every node in the subscription. Click the lightning bolt (latency test) icon at the top right of that group, and the client will test every node in it; within a few seconds, a latency value appears next to each node — green means low latency, yellow means higher, and a timeout means the node is currently unavailable.

Click a node with a low latency value; a selection marker appears next to the node name, indicating the group is now using that node. If the proxy group type is "Auto Select" (URL-Test), the client automatically picks the lowest-latency node for you, no manual selection needed. For how latency testing works and how to read the numbers, see the tips section of the FAQ.

Selection tip: Low latency doesn't mean high bandwidth. Prioritize nodes that stay under 200 ms with little fluctuation across repeated tests; nodes in a distant region (physically far-away data centers) naturally show higher latency, which is expected.

Next: enable the connection ↓

Turn on the system proxy

With the profile and node ready, traffic still won't flow through the client automatically — you need to turn on the system proxy switch. In Clash Verge, click "Settings" in the left sidebar, find the "System Proxy" toggle, and enable it — the client points your OS-level proxy settings to its local listening port (default 127.0.0.1:7890). Once enabled, your browser and most apps that follow system proxy settings will immediately route through the client. The system proxy toggle in Mihomo Party and FlClash sits in a similarly prominent spot on the settings or home page; on Android, CMFA takes over traffic as a VPN service — tap the start button on the main screen and allow the VPN connection in the system prompt.

Switch to TUN mode when needed

System proxy only works for apps that "respect proxy settings." Command-line tools, some games, and certain client software ignore the system proxy entirely — in those cases, enable "TUN Mode" on the settings page instead. It intercepts all traffic at the network layer via a virtual network adapter, regardless of whether the app cooperates. The first time you turn it on, Clash Verge will prompt you to install a system service (Windows) or request admin authorization (macOS / Linux) — just follow the prompts. For a comparison of how the two interception methods work, read the blog post "How Clash TUN Mode and System Proxy Work: A Comparison," and see the glossary for explanations of TUN, virtual network adapters, and related terms.

Note: Use either system proxy or TUN mode, not both — enabling both doesn't stack their effects and can instead cause loopback issues or confused rule matching. Stick with system proxy for everyday browsing and switch to TUN mode only when you need full traffic capture. Before enabling TUN mode, close other VPN or accelerator software to avoid conflicts with the virtual network adapter.

Next: verify it's working ↓

Check the connections panel

First, confirm from within the client. Click "Connections" in the left sidebar (some clients label it "Connection Info" or place it next to "Logs"), open any webpage, and new connection entries should keep appearing — each showing the target domain, the rule it matched, and the node it actually went through. The upload/download traffic counters on the home page should be climbing at the same time, confirming traffic is really passing through the client.

Check the exit IP

Next, verify externally. Visit any IP-checking website in your browser (search "IP lookup" to find one) — the exit IP and location it shows should match the region of the node you selected in step two. For example, if you chose a Hong Kong node, the check should show a Hong Kong IP. If you're worried DNS requests might bypass the proxy, see the blog post "Clash DNS Configuration and Leak Prevention: A Practical Guide" for further checks.

Verification checklist and troubleshooting

  • The profile card is selected, with no expiration or update-failure warnings
  • The proxy group has a node selected that passed the latency test
  • System proxy or TUN mode is enabled (and only one of the two)
  • The connections panel shows active connections with growing traffic counters
  • The IP-checking site shows a region matching the selected node

If any of these isn't satisfied, troubleshoot in this order: subscription validity → node latency → port conflicts → system proxy status → firewall. See the full walkthrough in "Troubleshooting Order for Clash Node Timeouts and Connection Failures"; more scattered issues are covered in the troubleshooting section of the FAQ page.

Done: Passing all five checks means setup is complete. From here on, you just need to renew the profile before it expires and switch nodes as needed — no need to repeat the process above.

NEXT

What to check out next

Once your first setup is done, these pages cover the most common advanced settings and troubleshooting needs.

FAQ

Four categories — basics, installation, usage tips, and troubleshooting — covering frequent issues like expired subscriptions and port conflicts.

Glossary

Concise explanations across five categories: proxy protocols, cores and clients, rule-based routing, DNS, and subscriptions/profiles — a companion reference for the tutorial.

Downloads for all platforms

Installers and system requirements for Windows, macOS, Android, and Linux clients, each labeled with its maintenance status.

Download Client