Usage Docs · Getting Started · About 10 Minutes

Clash Tutorial: Subscription Import and Connection Verification

Written for first-time users of Clash-family clients: install a client, import a subscription link, choose a proxy mode, enable the system proxy, and verify it works — four steps in order and you are up and running. Interfaces differ slightly across platforms, but the main flow is the same.

A note on interface differences.This tutorial follows the interface of Clash Plus, the cross-platform client. Clients such as Clash Verge Rev, FlClash, and Clash Meta for Android place buttons differently and use slightly different wording, but the main path — Profiles, Proxies, Mode, System Proxy — is identical; just look for the matching entries. If you have not installed a client yet, head to the downloads page to get one for your platform, then come back and follow along.

Before You Start: Install a Client and Have a Subscription Link Ready

You need two things before you begin: an installed client and a working subscription link. Get the client from the downloads page for your system — on Windows and macOS, download the installer and follow the wizard; on Android, install the corresponding APK; on iOS, get Clash Plus from the App Store. There are no tricky options during installation; just keep going.

The subscription link is issued by your service provider (often called an "airport" in Chinese communities) in your account dashboard. It is a full URL starting with http. The client needs it to fetch the node list, policy groups, and routing rules. Think of it as the living source of your configuration: when the provider adjusts its nodes, one tap on Update in the client syncs your local config to the latest.

The subscription link is also your account credential — your validity period and data allowance are tied to it. Do not post it publicly, share screenshots of it, or paste it into unknown subscription-conversion sites. The differences between subscription formats (Base64 vs. Clash YAML) and when conversion is appropriate are background reading you can save for later; both the YAML manual and the blog series cover them in detail, so we will not repeat that here.

The Walkthrough: Four Steps in Order

The actual process is just four steps: import the subscription, choose a mode, enable the proxy, and verify it works. The steps depend on each other — without a profile there are no nodes to pick, the wrong mode sends traffic down the wrong path, and without the system proxy no traffic passes through the client at all. So follow them in order, confirming each step before moving on. Once you are comfortable, daily use comes down to two actions: tap Update when the subscription nears expiry, and switch nodes when one feels slow.

  1. Step 1: Import the Subscription Link

    Path · Profiles → New → Import from URL

    Open Clash Plus and go to the Profiles page in the bottom navigation (Clash Verge Rev calls it Subscriptions; in FlClash it is Profiles in the left sidebar). This page lists all local profiles. It is usually empty the first time, with a New button in the center or the top-right corner.

    Tap New, choose an option like Import from URL, paste the full subscription link into the address field, give the profile a recognizable name — the provider's name works well — and save. Three things to watch when pasting: copy the entire string without truncating the parameters at the end; leave no spaces or line breaks at either end; and a subscription address starts with http — if what you have is a string of irregular text, that is a node share code, which uses a different entry point. Do not mix the two.

    After saving, the client immediately requests the configuration from that address. Back on the profiles list, a new card with a just-now update time means the fetch succeeded. Tap the card to select it (it highlights or shows a checkmark), then switch to the Proxies page — you should see several policy groups and rows of nodes. If no nodes appear, the link has likely expired or your current network is unreachable; go back and check.

    The nodes are registered, but which path your traffic takes is not decided yet — that is the next step.

  2. Step 2: Choose a Proxy Mode

    Rule / Global / Direct

    Clash-family clients offer three proxy modes. Rule mode follows the routing rules in the config: sites in mainland China go direct, sites outside China go through the proxy — this is the daily recommendation. Global mode sends all traffic through the currently selected node; use it only for troubleshooting or special needs. Direct mode sends nothing through the proxy, effectively the same as turning it off temporarily.

    Where to switch: in Clash Plus, the mode toggle at the top of the home or proxies page; in Clash Verge Rev, the three-way selector at the top of the Proxies page; in FlClash, a prominent spot on the dashboard. Switching takes effect immediately — no client restart or profile re-import needed.

    When in doubt, choose Rule mode. In Global mode, visiting sites in mainland China takes a detour, hurting speed and stability while burning node traffic for nothing; Direct mode is the same as no proxy at all. Here is how the three modes compare:

    ModeTraffic PathBest For
    RuleRouted by config: proxy outside China, direct withinDaily use (recommended)
    GlobalAll traffic via the selected nodeTroubleshooting, temporary needs
    DirectNo traffic via proxyTemporarily disabling the proxy

    The mode decides how traffic flows, but one master switch decides whether it flows at all — the system proxy.

  3. Step 3: Enable the System Proxy and Connect

    Toggle · SYSTEM PROXY / Set as System Proxy

    First pick a node on the Proxies page. Expand a policy group named something like Select Node, tap a node name in the list, and the selection highlights. There is usually a latency test button next to the nodes (a lightning or speed-test icon); tap it to test them in batch and pick one with low, stable latency. Policy groups, auto-select, and similar concepts are explained in the YAML manual — here you only need to know how to tap and pick.

    Windows: turn on the System Proxy switch in Settings or on the home page. Once enabled, an entry like 127.0.0.1:7890 appears in the system's network proxy settings, meaning system traffic now routes through the client. Note that UWP apps installed from the Microsoft Store are restricted by the system loopback rule and do not use this proxy by default; the restriction must be lifted separately — see the corresponding chapter of the YAML manual.

    macOS: check Set as System Proxy (or the same item in the menu-bar icon), and the proxy fields in Network preferences are filled in automatically. Android and iOS: tap the connect button on the main screen; the system shows a VPN permission prompt, and once allowed, a VPN icon appears in the status bar — the device-wide traffic is now handled by the client.

    The switch is on and a node is selected — in theory, you are connected. But "in theory" is worth nothing; take a minute to verify.

  4. Step 4: Verify the Proxy Works

    Exit IP · Target Site · Connection Log

    Method one: check the exit address. Open any IP lookup site in the browser; in Rule mode, visiting a lookup site outside China should show the region where your node is located. Switch to Global mode and refresh — the address should change accordingly. If it does not, your traffic is not going through the proxy.

    Method two: check a target site. Visit a site outside China that normally fails to load; if it opens, the proxy is working. This is the most direct vote.

    Method three: check the connection log. The client's Connections or Logs page scrolls every connection in real time: the domain requested, the rule matched, and the node used. Browse a few pages — new records scrolling here means traffic really passes through the client; no records at all means the system proxy never took over.

    Passing either of the last two methods means you are done. If neither passes, troubleshoot in the order below.

Not Working? Check These Five Spots in Order

When verification fails, nine times out of ten the cause is one of the five below. Go through them in order, and after ruling out each one, return to Step 4 and verify again.

  1. Is the system proxy switch really on?It is common for other software to grab the switch or for the system setting to be reverted. Toggle it off and on again, then restart the browser.
  2. Is the current mode Direct?Everything looks normal in Direct mode, but it equals no proxy at all — switch back to Rule mode.
  3. Has the node gone dead?Re-run the latency test on the proxies page and switch to a node with normal latency; if the whole group times out, the problem is likely on the provider's side.
  4. Has the subscription expired or run out of data?Go back to the profiles page and tap Update once; if the update fails, or all nodes turn gray afterward, check your plan status in the provider's dashboard.
  5. Is another proxy app conflicting?Other proxies or game boosters running on the same machine fight over the system proxy settings — quit them all and try again.

If all of the above are ruled out and it still fails, the problem is most likely at the DNS resolution, TUN mode, or firewall-permission layer — advanced topics covered systematically in the troubleshooting chapter of the YAML manual.

Going Further: From Working to Well-Tuned

That concludes the tutorial. Daily use leaves only two actions: tap Update on the profiles page when the subscription nears expiry or nodes misbehave, and run a latency test and switch nodes on the proxies page when things feel slow. Leave everything else to Rule mode's automatic routing.

To go further, there are two directions. The YAML manual covers the full structure of the config file: general fields like port and mode, proxy node fields, policy group types, rule syntax, and override merging — after reading it you can understand and modify your own config. The blog offers topics like the kernel lineage (original Clash, Meta, and mihomo) and per-platform deployment details, worth picking through by interest.