CLI proxy

WSL2 Through Clash Verge: Point the Subsystem at the Host Proxy, Not Tun Alone

Clash works in Windows, but WSL2 curl/git/npm still direct-connects. Expected: WSL2 has its own network namespace and does not inherit the Windows system proxy. Point the subsystem at the host proxy explicitly.

Order: prove the Windows browser via Clash first, then configure WSL. Don’t debug WSL while the host is broken.

Minimal setup: host IP + mixed port

Find the Windows host IP from WSL (the command differs for mirrored vs older NAT modes). Then export the proxy vars using the host IP and the Clash mixed port:

export http_proxy=http://HOST_IP:MIXED_PORT
export https_proxy=http://HOST_IP:MIXED_PORT
export ALL_PROXY=socks5://HOST_IP:MIXED_PORT

Use the port shown in Clash settings. Enable Allow LAN and allow the port in Windows Firewall. Persist in shell rc files—a plain export dies with the window. Wrap only some commands in functions if you don’t want global proxying.

Tun vs env vars: which covers what

ApproachCoversGotchas
Env vars (http_proxy / ALL_PROXY)CLI tools that read them: curl, git, npmMust be set in each new shell; stale values linger
Mirrored networkingWSL sees the host stack more directlyBehavior varies by WSL version
TunWhole Windows app setWSL2 usually still needs env vars or mirrored mode

Git, npm, Docker, and IDEs

Tun mainly covers Windows apps; WSL2 usually still needs env vars or mirrored networking. Git/npm/Docker-in-WSL read proxies slightly differently—watch for read timeout vs connection refused vs DNS failure. Remote-WSL IDE terminals need the same env. Corp VPN + WSL + Clash: change one layer at a time. Corporate MITM certs break npm with trust errors—not a “wrong node” problem.

Failures and leftovers

Connection refused: Allow LAN / firewall / host IP. Timeouts: test on the host first. DNS mismatches: simplify DNS, then retest the proxy. After disabling the proxy, open a new shell so old env vars die. Don’t mix WSL1 and WSL2 advice.

Done when

WSL outbound matches host expectations; git/npm work when proxied; new shells don’t keep stale proxy env. Also see CLI proxy and ports.

Prove Windows proxy first

Before deep WSL debugging, confirm Clash works in a Windows browser and Connections shows rows.