Configuration Reference / GLOSSARY

Clash Glossary

From protocol names to iOS network settings. Browse terms by category, then check the corresponding options in your client. Availability can vary across cores and clients.

Proxy Protocols

Protocols define how the client connects to the server. Along with the protocol name, check the transport method and connection parameters.

Shadowsocks(SS)

A proxy protocol that uses encryption to connect to a remote server. Configure the server address, port and encryption method, making sure the client and server settings match. SS in a configuration refers to the protocol type, not a specific client.

VMess

A proxy protocol in the V2Ray ecosystem, typically used with a user ID, server address and transport settings. Two VMess configurations may use different transports. If a connection fails after import, check the settings against the source configuration before switching outbound modes.

Trojan

A proxy protocol that typically connects over TLS. Along with the address, port and authentication details, certificate settings can affect whether a connection succeeds. Selecting Trojan in the client only determines how these parameters are interpreted; the connection still depends on the server configuration.

VLESS

A proxy protocol that relies on the transport layer for encryption and can be paired with different transport methods. Check the user ID, transport type and security settings together. Not every client labeled Clash supports the same VLESS combinations; support depends on the core in use.

Cores and Clients

The user interface and connection handling are separate layers. When a configuration is incompatible, first identify which layer is causing the problem.

Clash Core

The core program that reads configuration files, matches routing rules and handles connections. It is usually separate from the app interface. Clients with similar appearances may use different cores, so their supported protocols and configuration fields can vary.

mihomo

A core project that builds on Clash Meta’s features and often appears in client core details and configuration documentation. Its supported protocols and extended configuration fields may differ from those of the original Clash. Before using a sample configuration, check which core it targets to avoid copying incompatible fields.

Client

An app that provides controls for importing configurations, choosing an outbound mode and toggling connections. Feature support also depends on the integrated core, app version and system permissions. Choose a client for your device’s operating system, then check which configuration types it supports.

Profiles and Subscriptions

These terms explain where configurations come from, how they’re stored and where connection details are defined.

Subscription Link

An address used to fetch remote configuration. After importing a link, the client typically saves the retrieved content as a selectable profile. Use “Update Subscription” to fetch the remote content again. A successful update only means the configuration was retrieved; it doesn’t guarantee that every connection in it works.

Profile

A configuration you can select in the client, imported from a subscription link or loaded from a local file. Separate profiles are useful for keeping different rules and connection settings apart. Before switching profiles, check the displayed name and last-updated time so you don’t edit a different profile by mistake.

YAML

A common data format for Clash configuration files, often named config.yaml. Indentation defines the hierarchy; for example, child entries under dns must use consistent indentation. Incorrect nesting or a missing colon can prevent the client from parsing the file.

Proxy Node

A proxy connection defined in a configuration, usually with a server address, port and protocol-specific parameters. A “node” is a configuration object, not a specific protocol. Seeing a node in the list only means the configuration was read; test an actual request to confirm it connects.

Routing Rules

The outbound mode determines how rules are used; the rules themselves determine which outbound a matching request uses.

Rule Mode

Matches requests against rules in the configuration, then sends them through a proxy, directly or to another outbound. Common match conditions include domains, IP addresses and rule sets. It does not automatically pick the fastest connection—the result depends on the rules, their order and the outbound settings.

Global Mode

Typically sends requests through the currently selected proxy outbound instead of routing them rule by rule. To compare how a request is handled in rule mode, you can switch modes temporarily. When finished, switch back to your preferred everyday mode and review the rules.

Direct Mode

Connects requests directly to their destination without using a configured proxy outbound. This can help you check whether the device’s network works normally, but it doesn’t prove the configuration is correct. Mode names and traffic coverage can vary across clients; check the documentation for your app.

GeoIP

Data or rule conditions used to match traffic by the region associated with an IP address. Results depend on the geolocation database, and updates to that database can change classifications. For domain requests, subsequent matches can also depend on the resolved address and rule order.

Rule Set

A group of matching rules that a configuration can reference, making long rule lists easier to maintain separately. The client loads or updates the set according to the configuration; updating it may be separate from updating the main configuration. If routing behaves unexpectedly, check where the set is referenced, its contents and the match order.

DNS and Networking

Name resolution and connection setup are related, but a successful lookup does not mean the connection will work.

DNS

The process of resolving a domain name to a network address, or the service that performs the lookup. The dns section in a Clash configuration controls how related requests are handled. Before changing DNS settings, check whether the client handles queries and whether the current network can resolve names normally.

Fake-IP

An address-mapping method used in enhanced DNS mode: an IP address mapped to the domain is returned to the app first, then the core associates later connections with the original domain. It is commonly configured as enhanced-mode: fake-ip. Some local-network devices or apps that rely on the actual resolved address may need separate handling in the filter configuration.

DNS Leak

A domain lookup expected to be handled by the client instead follows a different resolution path. This is not the same as a website failing to load, and a single address test isn’t enough to confirm a leak. Check system DNS, the client’s traffic coverage and the resolution settings in the configuration.

Latency

The time, usually measured in milliseconds, from sending a test request to receiving a response. It varies with the test destination, network conditions and connection state, and is not the same as download speed. For a fair comparison, use the same test method and remember that low latency doesn’t rule out app-level errors.

iOS System Features

On iPhone and iPad, connection controls also depend on system permissions and the types of network traffic the app can handle.

iOS VPN Configuration

A network connection configuration authorized by the user in iOS. The first time you launch a client that uses these system capabilities, your device may ask you to approve adding the configuration. Seeing a VPN configuration in Settings does not mean a subscription has been imported or its rules are active.

Network Extension

An iOS system framework that lets apps with the required permissions handle network connections. A client can use it to receive and process certain types of traffic, depending on its implementation. If the connection switch won’t turn on, first check system permissions and any error message from the client.

TUN Mode

A method for receiving and handling traffic through a virtual network interface. On iOS, how a client exposes this capability depends on its Network Extension implementation, so don’t assume desktop setup steps apply. When checking the connection status, also verify the active profile, outbound mode and system permissions.

Local Network Connections

Connections between a device and other devices on the same local network, such as opening your home router’s admin page. If those devices become unreachable after enabling the client, check local network settings, DNS resolution and routing rules. Allowing local network connections is different from allowing other devices to connect to your device.

Download the Client