Proxy Modes and System Proxy FAQ
Compare Clash Rule, Global, and Direct modes, then troubleshoot system proxy failures, bypassed apps, port conflicts, exit-time outages, browser proxies, DoH, and extensions.
First determine whether traffic enters the client
The system proxy, per-app proxies, browser extensions, and TUN create different traffic paths.
What Is the Difference Between Rule, Global, and Direct Modes?Rule mode matches policies through rules. Global mode sends most traffic to the selected policy group. Direct mode tries to keep traffic from passing through proxy nodes.What If an App Still Bypasses Clash After the System Proxy Is Enabled?The system proxy affects only apps that honor the operating system's proxy settings. Some games, command-line tools, store apps, and standalone proxy software may ignore it.What If a Local Port Is in Use and the Proxy Port Cannot Start?Clash clients commonly open HTTP, SOCKS, mixed-port, and external-controller ports. A port conflict can break the system proxy or control dashboard.What If the Network Still Does Not Work After Exiting Clash?After Clash exits, connectivity may fail because of a stale system proxy, TUN/VPN interface, changed DNS, a browser's manual proxy, or another proxy tool still controlling traffic.What If a Browser Bypasses Clash Because of Its Own Proxy, DoH, or an Extension?A browser can bypass the system proxy because of a proxy extension, built-in secure DNS, a developer-tools network proxy, a user profile, or an enterprise policy.
