On Windows, enabling Tun, installing a driver, or seeing "admin required / service not installed" usually points at Service Mode. It is not another proxy toggle. It lets Clash Verge Rev run as a system service with enough rights to create a virtual NIC and capture traffic. People misread Tun failures, flaky startup proxy, and core-communication banners as "dead nodes." Checking whether the service is healthy often saves an hour.
Tun itself: Tun mode, Tun start failed. Builds: download center. Modes: three modes. Hand-filled fallback: mixed port. Here: what the service fixes, when you must install, when you can skip, install/accept, corporate / AV / VPN conflicts, and when to stop reinstalling the service.
What Service Mode actually fixes
System proxy only affects programs that read OS proxy settings. Games, some CLIs, some IM / AI tools ignore it. Tun needs a virtual NIC for those flows, and Windows usually wants elevated rights. Service Mode turns that elevation into a durable system service instead of gambling on "Run as administrator" every launch.
Missing or broken service symptoms: Tun toggle fails, permission errors, NIC create fails, core communication errors, Tun dead after sleep/wake. The browser on system proxy may still work—so half the stack looks fine. That pattern screams service/Tun layer, not a dead airport. Wake cases: sleep/wake offline. Banners: core communication.
When you must install, when you can skip
Install when: Tun is part of daily use; you need AI CLI / IDE / games that ignore system proxy; you want fewer admin prompts after boot.
Defer when: browser + system proxy is enough; corporate policy forbids local services or virtual NICs; you lack admin rights for now.
If you never touch Tun, forcing the service is optional. Once Tun is in the path, the service becomes a prerequisite. System proxy path: system proxy not working. Login/startup: startup proxy.
Install, accept UAC, and prove it
- Install from a verifiable package (download center)—skip mystery portable builds.
- In Settings, find Service Mode / Install Service and accept admin. If AV blocks, allowlist then retry.
- Do not stack other VPNs or game boosters yet. Enable Tun and see if it stays on.
- Open Connections; hit an app/site that normally ignores system proxy; confirm new rows.
- Disable Tun and confirm system proxy still works—you need a rollback path, not "Tun on = offline forever."
Service present but Tun still fails: follow Tun start failed—driver clashes, leftover TAP, firewall (firewall blocked). Half-finished in-app updates can also damage service-related files: app update failed.
Corporate images, AV, and stacked VPNs
Managed images often ban local services, driver installs, or silently block virtual NICs via EDR. You click Install, the UI blinks, the service never appears, Tun never sticks. Reinstalling as a normal user will not beat policy—need IT allowlisting or a personal machine to prove "is this the image?"
At home, stacked VPNs matter: ExpressVPN, corporate SSL VPN, some accelerators fight NICs and routing tables. Exit other VPNs, leave Clash alone, then install service and enable Tun. High CPU / fake-dead service ideas: CPU/memory. SmartScreen / admin install prompts: SmartScreen and admin.
Acceptance—and when to stop reinstalling the service
Do not trust toggle color alone. Useful signals: the service exists and is Running; with Tun on, an app that ignores system proxy leaves Connections rows; with Tun off, the browser still works via system proxy. Missing any one means the service/Tun layer is not ready.
- Service installed and visible in Services (name depends on your build).
- Tun stays on; target app traffic appears in Connections.
- After Tun off, system proxy path still works.
Still failing: reinstall service as admin → clear other VPN/TAP → AV allowlist → optional safe config reset (back up subscriptions). If you reinstall the service twice in one day with zero Connections rows, stop and chase drivers/policy instead of clicking Install again. Index: common errors. Clean builds: download center.
Install vs skip at a glance
| You need… | Action |
|---|---|
| Browser only via system proxy | Skip the service |
| Tun for games / AI CLI / IDE | Install Service Mode first |
| Fewer admin prompts after boot | Install Service Mode |
| Corporate EDR blocks drivers | Need IT allowlisting; reinstall won’t help |