System proxy covers apps that honor OS proxy settings. Tun uses a virtual adapter to pull more traffic into Clash—useful for games, CLI, and some AI tools. It isn’t automatically “better,” and can break connectivity or make rollback harder if misused.
If the browser already works, don’t force Tun for web browsing. Deep dive: Tun & AI; start failures: Tun start failed. Overview: getting started.
System proxy vs Tun at a glance
| System proxy | Tun mode | |
|---|---|---|
| Covers | Apps honoring OS proxy | More traffic incl. games / CLI / AI |
| Setup | Toggle in OS | Service mode + virtual adapter |
| Rollback | Flip the toggle | Restore adapter / routes |
| Best for | Web browsing | CLI / AI / games ignoring OS proxy |
Enable and preflight
Install service mode / approve permissions, then toggle Tun. Preflight: disable other VPNs/accelerators; allow the virtual adapter in AV; note system proxy for rollback. No admin rights at work → fall back to system/in-app proxy.
Before Tun, confirm the subscription has nodes and the browser path already works. Separate “no nodes” (no nodes) from “Tun isn’t capturing”—they are different fault trees.
Prove Tun is capturing
Connections should show the target app. Still bypassing: rules DIRECT, DNS issues, dead nodes (routing, DNS). Tun + system proxy together: trust the connections page, not “more toggles.”
For CLI checks, hit a host that must use the proxy and watch for matching process/host rows. Browser rows without terminal rows usually means Tun didn’t cover that process, or a rule sent it DIRECT.
Sleep, VPN, game boosters
After sleep/Wi‑Fi changes, toggle Tun or repair service. Corp VPN vs Tun—one layer only. Don’t stack game boosters with Tun; both rewrite routes. VMs/containers have their own stacks—don’t expect host Tun to cover guests automatically.
Phone-via-PC uses Allow LAN (Allow LAN); don’t merge that troubleshooting with Tun capture problems.
Resources and when to disable
Weak PCs feel Tun more (CPU/RAM). Browse on system proxy; enable Tun for games/CLI/AI. After disable, confirm routes/adapters recovered.
Before uninstalling, turn Tun off and restore system proxy, then uninstall—otherwise you may get “no internet” leftovers (uninstall cleanup). Builds: download center. Prefer system proxy when it is enough; Tun widens capture—it is not a default-on badge.