Help Center / FAQ

Clash for iOS FAQ

Find answers by device and symptom, from importing a configuration to troubleshooting connections. Desktop TUN, system proxy, and UWP loopback issues are covered separately under troubleshooting.

01 / Concepts & Modes

Getting Started

Learn the difference between clients, configurations, and connection modes.

Is Clash a core, a configuration file, or an iPhone app?

Clash usually refers to a proxy core that handles connections based on a configuration, along with its surrounding ecosystem. On a phone, you install a client app with a user interface. A configuration file defines proxies, DNS, and routing rules; a subscription is one way to obtain and update that configuration. Check the name of the client you’re using, then follow its import steps. A configuration file is not an installation package.

What’s the difference between a subscription link, a configuration file, and a proxy node?

A subscription link is an address used to fetch a configuration. The configuration file is what the client reads, usually containing proxy entries, proxy groups, and rules. A node is one of the proxy endpoints you can select. After importing a subscription, make sure the configuration is active and check the selected proxy in its proxy groups. Subscription URLs may contain account details, so don’t share them in public screenshots or support posts.

Which mode should I use: Rule, Global, or Direct?

For everyday use, start with Rule mode: requests are routed according to the rules in your configuration. Global mode sends proxy traffic through the selected proxy and can help with short-term troubleshooting. Direct mode bypasses the proxy. Changing modes won’t fix an expired subscription or an unavailable node. If a site behaves unexpectedly, check the active configuration’s rules and proxy groups first.

Is the iPhone connection switch the same as a computer’s system proxy?

No. An iPhone client usually routes the relevant traffic through an iOS VPN configuration, which requires system approval the first time you connect. A desktop client’s system proxy usually changes the proxy settings provided by the operating system; whether an app follows those settings depends on the app. When troubleshooting, identify the device and how its traffic is routed, then check the client’s connection status.

02 / Import & Permissions

Platform Notes

Start with system permissions, then check where the configuration came from.

How do I allow a VPN configuration after installing the app on iPhone?

Import and select a configuration in the client, then turn on the connection switch. When iOS asks to add a VPN configuration, tap Allow and complete any device verification requested by the system. Return to the client to check the connection status. If you dismissed the prompt, try connecting again. Also check Settings for existing VPN configurations to avoid connecting multiple conflicting VPN services at once.

How do I import a Clash subscription link on iPhone?

In the client’s Configurations or Profile screen, choose the option to download from a URL, paste the full subscription link, and save it. Wait for the download to finish, then set the new configuration as active. If the client reports a format error, check that the URL returns a supported configuration rather than a sign-in page or regular webpage. Button names vary slightly between clients, so follow the options shown in your app.

What should I do if a subscription link expires or fails to update?

Check that the subscription URL is complete and that your account or subscription is still active. An old node list alone doesn’t confirm that an update succeeded. Make sure your phone can reach the subscription service, then refresh the configuration manually and check the error message. If the response is a sign-in page, empty content, or an unsupported format, ask the subscription provider to verify the URL and format. Keep a working copy of your previous configuration for comparison.

What should I check if importing a local config.yaml fails?

Check the file extension and the import methods supported by your client. Then verify that YAML indentation uses consistent spaces. Top-level keys such as proxies, proxy-groups, and rules must be at the correct level, and proxy names referenced by a group must match the entries. Don’t save explanatory text copied from a webpage into the file. Try importing the original configuration first, then make changes one at a time to find the issue.

03 / Configuration Management

Advanced Config

When switching configurations, check for changes to proxy groups and DNS settings.

How do I switch between Profiles, and do I need to reconnect afterward?

Select the Profile you want in the configuration list and confirm it’s marked as active. Some clients reload it immediately; others require you to disconnect and reconnect. Profiles may have different proxy groups and rules, so don’t assume the same proxy selection applies after switching. If something stops working, check the active configuration name, connection status, and proxy group selection.

When should I update a subscription, and will an update overwrite manual changes?

Refresh the configuration manually when the subscription provider changes proxy entries or rules, or when existing nodes stop working. Updating a URL-managed configuration may replace its local contents with the remote version. If you edited a subscription-generated file, save a separate copy as an independent configuration first. After updating, check the active Profile, proxy groups, and rule mode—not just the update notification.

Can Fake-IP DNS mode affect devices on my local network?

Fake-IP returns mapped addresses for eligible domains, and the core uses those mappings to handle connections. Local network device discovery, some games, and apps that rely on real DNS responses may need additional rules. If you run into problems, compare behavior in Rule and Direct modes, then check dns.enhanced-mode and fake-ip-filter in the configuration. Don’t replace the entire configuration without understanding its current DNS settings.

When should I enable Allow LAN?

Enable Allow LAN only if other devices on the same local network need to use this device as a proxy. You’ll also need to check the listening address and port, the device firewall, and network reachability. Turning on the switch alone doesn’t configure the other devices. If you only use the client on this device, you usually don’t need to expose a proxy listener.

04 / Troubleshooting by Symptom

Quick Answers

Confirm your device is online, then check the configuration, permissions, and traffic routing.

What should I do if the iPhone VPN switch won’t turn on or there’s no internet after connecting?

Make sure a working configuration is selected and iOS VPN access has been approved. Then check the system VPN settings for another active connection. If the VPN connects but you can’t access anything, first confirm the phone can get online without it, then check the active proxy group, node, and rule mode. Temporarily disconnect other VPNs or network-filtering apps and try again. Check the client log for the first specific error.

A node passes its speed test, but connections time out. What should I check first?

A speed test only shows whether a specific target was reachable at the time of the test; it doesn’t guarantee that every request will work. Check that your phone’s network, active Profile, and proxy group still point to the same node. Try different destinations to tell a single-site issue from a general timeout. Then check the logs for DNS, connection, or authentication errors. If multiple nodes time out, review the subscription details and your device’s network.

How do I fix a permissions error when enabling Clash TUN mode on desktop?

TUN requires the client to create or manage a virtual network interface. The permissions needed vary by operating system and client. Read the permission prompt in your client, follow its settings page to grant system access or install the required service, then enable TUN again. If it still fails, check whether an existing VPN, virtual adapter, or security app is using the interface. iPhone system VPN approval is separate from desktop TUN permissions.

Why do some apps still bypass the proxy when Windows system proxy is enabled?

The system proxy only works with apps that read those settings. Some programs use their own network configuration or connect directly. Make sure the client is running and the system proxy is enabled, then test with a browser. If only one app is affected, check its own proxy settings. If you need to route more traffic, see whether your client supports TUN mode and check its permission requirements. Don’t keep changing ports without a reason.

A Windows UWP app can’t use the local proxy. How do I check loopback access?

Some UWP apps are restricted by Windows network isolation and can’t connect directly to a local proxy address. First confirm that a regular desktop app can connect through the same proxy port, then check whether the UWP app has loopback exemption. In Windows Terminal, run CheckNetIsolation LoopbackExempt -s to view the current list. To add an exemption, verify the target app’s package family name, then follow the loopback setup instructions for your client.

Download Client