TUTORIAL

Clash Setup Tutorial: From Subscription to Connection in 4 Steps

Clear goal: once you have a subscription link, finish importing, picking a mode, connecting, and verifying within ten minutes. Each step spells out exactly where to click, what you should see, and what comes next. Deeper mechanics and advanced tricks live in the Beginner to Advanced Guide.

Before you start: this page assumes two things are already in place — first, a Clash client for your platform is already installed; if not, grab it from the download page; second, a subscription link in hand, issued by your service provider's dashboard. For what a subscription link is and where it comes from, see the "Subscriptions & Profiles" category in the glossary.
Note on interface differences: menu naming isn't identical across clients. This page uses Clash Verge Rev as the desktop reference and Clash Plus as the mobile reference; in other clients, "Subscription" may be called "Profiles," and "System Proxy" may be called "Set as System Proxy" — just look for the equivalent spot, since the workflow is the same. See the client comparison for feature differences across clients.

STEP 01

Import the Subscription

After this step: a profile card appears in the client, and the node list is not empty.

A subscription link is a full URL starting with https://, generated by your provider; opening it returns a configuration file containing nodes and rules. The first thing to do is copy it in full — the number one cause of failure is a link that's missing its trailing parameters. Copy it directly from the "Copy Subscription" button in your provider's dashboard rather than selecting it by hand.

Desktop (Clash Verge Rev)

Open the client and click "Profiles" in the left sidebar. There's an input box at the top of the page — paste the subscription link in and click "Import" on the right. Within a few seconds a profile card appears below, showing the profile name, node count, traffic usage, and update time. Click the card to select it (a highlight appears on its edge), which means the profile is now active. If the card appears but shows 0 nodes, click the refresh button on the card to fetch it again.

Mobile (Clash Plus, iOS / Android)

Open the app, go to the "Profiles" page (visible directly on the home screen in some versions), tap the plus icon in the top right, choose "Import from URL," paste the subscription link, and confirm. On iOS, a system dialog will ask to "Add VPN Configuration" the first time you use it — this is a system-wide requirement iOS applies to all proxy apps; tap "Allow" and complete the verification as prompted. This only needs to be done once. After a successful import, the corresponding entry appears in the profile list; tap it to select it as the active profile.

If the import fails

Check three things in order: whether the link is complete with no extra spaces; whether the subscription is in Clash format — some providers offer different subscription URLs for different clients, so pick the one labeled Clash, and if the format doesn't match, use a subscription converter, covered in the glossary; and whether your current network can reach the provider's domain directly — if the provider's domain itself is blocked, complete the first import over mobile data or another network.

Note: a subscription link is equivalent to your account credentials — anyone who gets it can use your traffic. Don't post it in public groups or share screenshots of it.

Once the profile card is in place and the node list isn't empty, the import is done. Next, decide how traffic gets routed — on to step two.

STEP 02

Choose a Proxy Mode

After this step: the mode is set to rule mode, and policy groups have nodes assigned.

Clash has three basic proxy modes that determine how traffic is routed:

  • RULE mode: traffic is matched against the rules in the profile one by one — traffic matching a direct rule goes direct, traffic matching a proxy rule goes through a node. The default choice for daily use.
  • GLOBAL mode: all traffic goes through the proxy node without exception.
  • DIRECT mode: all traffic bypasses the proxy entirely, effectively pausing traffic splitting.

For the detailed mechanics of each mode and rule matching order, see the "Proxy Modes & Policies" category in the glossary — the takeaway here is simple: use rule mode as your default. The rule sets bundled with your subscription already handle the direct-vs-proxy split correctly, so under rule mode local sites load directly and sites outside your region route through a node automatically, giving you the best speed and traffic efficiency. Switch to global mode only in two temporary cases: a site isn't behaving because the rules don't cover it, or you need to force every app through the proxy — switch back afterward. Use direct mode for troubleshooting — if you suspect the proxy is interfering with an app, switching to direct once confirms it.

Where to switch

Desktop: on Clash Verge Rev, the top of the "Proxies" page in the left sidebar has three mode tabs — click to switch, and the active mode is highlighted. Mobile: Clash Plus offers the same three options at the top of the home page or "Proxies" page. Switching takes effect immediately with no need to restart the connection.

Assigning nodes to policy groups

Still on the "Proxies" page, below the mode tabs is the list of policy groups. A policy group is a set of nodes — common ones include "Auto Select," "Manual Switch," and groups organized by region. Expand a policy group to see its nodes, and click one to select it. For a first-time setup, either set the main policy group to "Auto Select" (the client picks the fastest node by latency), or manually pick a node that's geographically close. The selected item is clearly highlighted. For how policy group hierarchy works, see the corresponding chapter of the Beginner to Advanced Guide.

With mode set to rule and a node selected, everything's ready — next, flip the switch on.

STEP 03

Turn On the Connection

After this step: the client shows connected, and system traffic starts flowing through Clash.

Once the subscription is imported and a mode is chosen, the Clash core has already opened a proxy port locally, but system traffic hasn't been handed to it yet. This step connects the two.

Desktop (Windows / macOS / Linux)

In Clash Verge Rev's "Settings" page, find the "System Proxy" switch and turn it on. This points the operating system's proxy settings at the local port Clash is listening on (7897 or 7890 by default, depending on the client), after which your browser and most software that respects system proxy settings will route through Clash. Once enabled, the client icon in the taskbar or menu bar usually changes color or gets a badge to indicate the proxy is active. Some software that ignores system proxy settings (certain games, command-line tools) needs TUN mode to be intercepted; TUN is an advanced topic not covered here — see the TUN chapter of the Beginner to Advanced Guide.

Mobile (iOS / Android)

Mobile is more direct: tap the main switch on the app's home screen (usually a prominent round button or toggle). Android will prompt a system VPN connection request the first time — tap "OK"; on iOS, if the VPN authorization was completed in step one, it connects right away. A successful connection is unmistakable: a VPN icon appears in the status bar, the status text in the app changes to connected, and some clients start showing real-time upload/download numbers.

What you should see after connecting

Back on the client's main screen, a healthy state looks like: mode shows RULE, the active profile name is correct, and traffic counters tick up as background apps run. If the switch flips itself back off right after turning on, it's usually a syntax issue in the profile or a port conflict — go back and refresh the subscription in step one; on mobile it might also mean the system VPN permission wasn't fully granted, so check the VPN entry in system settings to confirm the Clash client is allowed.

Switch on, status healthy — last step: confirm traffic is actually routing the way it should.

STEP 04

Verify It Works

After this step: you've confirmed the proxy chain actually works and know how to troubleshoot it.

"Connected" only means the switch is on — it doesn't guarantee traffic is actually flowing through a node. Verify at the three levels below in order; the setup only counts as working once all three pass.

Check the client's connection log

Clash Verge Rev has a "Connections" page in the left sidebar; mobile clients have an equivalent connections or log view. Open any webpage and check back here: new connection entries should keep appearing, each showing the destination domain, the rule it matched, and the node (or direct route) it actually used. If this is completely empty, system traffic isn't reaching Clash at all — go back to step three and check the system proxy switch.

Visit a target site

Open a site in your browser that you normally can't reach without a proxy. Under rule mode it should load fine; at the same time, open a local site — it should load instantly and show up as a direct connection in the connection log. If both behave as expected, rule-based traffic splitting is working correctly.

Check the exit IP location

Visit any IP lookup site and check whether the location shown matches the region of the node you selected. This is the most direct evidence: if the location changed, the proxy chain is fully working. Note that under rule mode, some IP lookup sites may be matched to a direct rule, in which case seeing your local IP is expected — try a different overseas lookup site, or switch temporarily to global mode to verify.

Troubleshooting order if it's not working

  1. Test node latency.

    Click the latency test button on a policy group in the "Proxies" page — a normal latency reading means the node is usable; a timeout means try a different node, and if the entire group times out, the subscription has likely expired or the provider is having issues, so check the provider's dashboard.

  2. Check mode and rules.

    Confirm you're in rule mode and that the target site actually matched a proxy rule — search the destination domain in the connection log to see which rule it hit. If a particular site isn't covered by any rule, temporarily switch to global mode to compare; if it works there, it's a rule issue — see the traffic-splitting chapter of the guide for the fix.

  3. Check for environment conflicts.

    Browser proxy extensions, other proxy software, and leftover manual proxy settings on your system all compete with Clash for traffic. Disable similar software and extensions, keep only Clash's setting active in the system proxy settings, and try again.

Once all three verification levels pass, the first-time setup is complete. From here, day-to-day use mostly comes down to two actions: switch nodes when one gets slow, and refresh the subscription after your provider updates it.

NEXT

After You're Done

The basic connection is working — continue as needed:

  • To understand traffic splitting, custom rules, TUN mode, and profile structure, read the Beginner to Advanced Guide — this site's in-depth guide, from core concepts through advanced maintenance.
  • Unsure about a term used in the tutorial? Check the glossary, organized by proxy protocols, modes and policies, traffic splitting, and more.
  • If your current client feels clunky, check the client comparison for a better fit — the import process is the same as on this page.