When Should I Enable TUN Mode?

TUN is useful when an app ignores the system proxy, UDP traffic must be captured, or more system traffic needs rule-based handling. Browsers and other apps that already honor the system proxy usually do not need it.

  • TUN Mode and Permissions
  • Concept overview
Short answer

TUN is necessary when an app ignores the system proxy, UDP must be captured, or more system traffic needs rule-based handling. Apps such as browsers that follow the system proxy generally need no additional capture. Once you confirm the system proxy cannot cover the target traffic, enable TUN, DNS hijacking, and automatic routing according to the client documentation, then retest immediately.

First determine whether the target traffic needs TUN

If the target app already follows the system proxy, do not enable TUN first. Continue only when the request never appears in the connection list.

Can the target app configure an HTTP/SOCKS proxy?

Does the app's request never appear in the connection list?

Do you need to handle UDP, games, voice, or command-line tools?

Does the current system allow creating a TUN or VPN interface?

Once confirmed, enable it this way

  • First confirm that the standard system proxy cannot meet the need(See System Proxy FAQ)
  • Back up the configuration and record the original proxy settings before enabling TUN(See TUN device guide)
  • Enable TUN, DNS hijacking, and automatic routing according to the client documentation
  • After enabling it, use the connection list to confirm that the target request enters Clash

TUN is not a speed-optimization switch

TUN can conflict with other VPN software, enterprise security tools, or virtual adapters

On mobile devices, TUN usually appears as system VPN permission