Clash Verge can manage a VPN or proxy subscription on Windows 11, but installing the app is only one part of the setup. You also need a valid subscription link, an up-to-date profile, a selected server, and a routing mode that matches what you want to connect. Finally, test the connection from Windows and from the apps you actually use. A green status in the client is useful, but it does not by itself prove that every program is using the selected route.
This guide walks through a clean setup: prepare Windows, install Clash Verge, import and refresh a subscription, select a server, and verify the result. It also covers common permission, update, and connection issues. Menu names can differ slightly between app versions, so use the equivalent control if your interface is worded differently. For a general overview of supported setup options, see the quick-start guide.
Before you install Clash Verge
Get the subscription link from the provider account or setup instructions you trust. A subscription link is a credential: anyone who obtains it may be able to use or import the configuration associated with your account. Do not paste it into public chats, screenshots, online URL checkers, or support posts. If you think it has been exposed, use the provider’s account tools or contact its support team about replacing it.
Check that the link is intended for a Clash-compatible client. Subscription formats and supported proxy protocols can vary. A provider may offer separate links for different clients, or require a conversion option before a link can be imported. If the link is presented as a file rather than a URL, follow the provider’s instructions for that format instead of assuming the two are interchangeable. Do not edit the link unless the provider specifically asks you to.
Before installation, close other proxy or VPN applications that may take control of Windows proxy settings or create a competing tunnel. You can keep them installed, but running two traffic-routing clients at once makes troubleshooting harder: one app may replace the system proxy settings while another is still active. Save work in open apps, and make a note of any custom proxy settings you already use so you can restore them if needed.
- ✅ Obtain the subscription URL from the provider’s account or official setup instructions.
- ✅ Confirm that the subscription is compatible with Clash Verge or the core it uses.
- ✅ Keep the URL private and avoid copying it into public troubleshooting tools.
- ❌ Don’t run multiple traffic-routing clients simultaneously while setting up the first one.
For the cleanest first test, use a normal home or mobile network and keep the setup simple. If you are on a managed work or school computer, policies may block installation, network drivers, or changes to system proxy settings. Do not try to bypass an organization’s device controls; ask the administrator whether this software and its network features are permitted.
Install Clash Verge on Windows 11
Download the Windows build from the project’s official distribution source or from a provider’s clearly identified setup page. Avoid repackaged installers and download sites that bundle additional programs. If you need the VPNQN client rather than Clash Verge, use the download page; the steps in this article are specifically for importing a subscription into Clash Verge.
Choose the installer that matches your Windows device and follow its prompts. If Windows displays a security or publisher warning, pause and verify that the file came from the source you intended. Do not dismiss a warning just because you are eager to continue. Once installation finishes, open Clash Verge from the Start menu. If the app asks to create or update a configuration directory, allow it to use its normal application location rather than moving configuration files while setup is in progress.
Some features require elevated permissions. In particular, a system-level tunnel may rely on a virtual network interface or driver, and Windows may ask for administrator approval when that feature is enabled or installed. Grant permission only when you understand which app is requesting it and have verified the app’s source. You can usually test basic subscription import and proxy operation without turning on every advanced option at the same time.
If the app will not open, first check whether Windows Security quarantined the installer or an app file. Review the alert details and verify the source before restoring anything. Also check whether your Windows account is allowed to install applications. Reinstalling repeatedly is rarely helpful until you know whether the problem is a blocked file, insufficient permissions, or an incompatible build.
5
setup stages in this guide
3
connection checks to compare
1
proxy client for the first test
Import the subscription and refresh its profile
Open Clash Verge and find the profile or subscription area. Depending on the version, it may be labeled Profiles, Subscriptions, or something similar. Choose the control for adding a remote profile, enter a recognizable name, and paste the full subscription URL into the URL field. Check that the beginning and end of the link have not been dropped, and make sure you have not included a space or quotation mark. Then save or confirm the import.
A successful import should create a profile entry or begin downloading configuration data. If the interface offers an update action, use it after adding the profile. Profiles can become stale, and the available server list is supplied by the subscription rather than permanently stored in the app. Wait for the update to finish before selecting a server. If the profile shows an error, note the error wording and check the causes below rather than repeatedly pasting the same link.
When more than one profile is listed, select the one you just added and confirm it is active. A saved profile is not necessarily the currently loaded profile. Look for a selected or active indicator in the profile list, then open the server or proxy selection area to see whether entries have appeared. Do not assume the profile imported correctly merely because its name is visible.
Subscription links may contain account-specific information and should be handled like passwords. If Clash Verge provides a profile preview, avoid sharing screenshots that show the full URL or sensitive configuration details. When asking for help, describe the error and the step where it occurred, but redact the link, account identifiers, and any private credentials.
Select a server and choose a routing mode
Once the profile has updated, open the proxy or server group view. Select a group first if the profile presents groups such as automatic selection, regional choices, or a list of individual servers. Then choose one available server. The names and group structure come from the subscription, so they differ between providers. If a group offers automatic selection, it may choose a route according to its configured rules; choosing an individual entry instead can make a first test easier to interpret.
Next, decide how traffic should be handled. Rule mode sends traffic according to rules in the profile; some destinations may use the proxy while others connect directly. Global mode generally sends a broader range of traffic through the selected proxy, subject to the client’s implementation and system settings. A system proxy setting typically directs applications that respect Windows proxy configuration, whereas TUN mode uses a virtual network interface to handle traffic more broadly. Exact behavior depends on the Clash Verge version, core, profile rules, and Windows configuration.
For an initial check, use the simplest mode that matches your goal. If you only need to test a browser and the system proxy is available, start there. If an application ignores the system proxy, that alone does not prove the subscription is broken; it may need a different mode or may not support that proxy path. TUN mode can handle more traffic, but it may require administrator approval and can interact with firewall, security, or other network software. Enable it only when needed, and change one setting at a time.
| Setting | Typical use | What to check |
|---|---|---|
| Rule mode | Use profile rules to decide which traffic is proxied or direct. | A destination may intentionally use a direct connection under the profile’s rules. |
| Global mode | Send a broader range of traffic through the selected proxy for comparison. | Confirm the mode actually changed and test more than one application. |
| System proxy | Route traffic from applications that follow Windows proxy settings. | Some apps ignore the system proxy or use their own network configuration. |
| TUN mode | Use a virtual interface when broader traffic handling is needed. | Check permissions, driver status, firewall prompts, and conflicts with other clients. |
Start the connection in Clash Verge and wait for the client to show that the selected route is active. If Windows asks for permission to add a network component, verify the app and request before approving it. Do not turn on system proxy and TUN settings indiscriminately just to make the status indicator change. The right combination depends on the traffic you want to route and the profile’s rules.
Verify the connection in Windows and your apps
Test in a consistent order. First, check the client: confirm the intended profile is active, the intended server or group is selected, and the connection is running. Second, open a reputable public IP lookup page in a browser that uses the system proxy. Compare the reported public IP and approximate location with the result when disconnected. A changed result is evidence that this browser request used a different exit, but a location database can be imprecise and a browser test does not represent every app.
Third, test the application you actually care about. A browser may follow Windows proxy settings while a game, desktop app, or command-line tool uses a different network path. If one application works and another does not, check the profile rules, app proxy support, and whether you have selected a mode that handles that application’s traffic. Test one app at a time so you can identify which setting changes the result.
If a website loads but behaves as though your location has not changed, consider more than the public IP. The browser may have cached data, use its own secure DNS setting, or be signed in to an account whose region is managed separately. A service may also apply account, payment, licensing, or device rules that a network route cannot change. Close and reopen the test page, compare a second site, and avoid treating one location label as a definitive diagnosis.
When the connection does not work, disconnect in Clash Verge and restore the original Windows proxy setting if the app did not do so automatically. Then reconnect and test again with only one mode enabled. If ordinary browsing returns only after disabling the client, review the active profile and Windows proxy configuration before making further changes. This controlled comparison helps distinguish an import problem from a routing-mode issue or a conflict with another network tool.
- ✅ Confirm the active profile and selected server before testing.
- ✅ Compare a public IP result before and after connecting on the same network.
- ✅ Test the specific app you intend to use; a browser result is not a whole-device test.
- ✅ Change one mode or setting at a time, then repeat the same check.
- ❌ Don’t post your full subscription URL, public IP, or private configuration in a public support thread.
Troubleshoot update, permission, and connection errors
The profile imports but contains no usable servers: refresh the profile and check whether the provider’s instructions specify a client-compatible link or an account activation step. Confirm that the selected profile is the one you updated. If the provider has multiple subscription formats, do not substitute a link intended for a different client. If the list remains empty, share the non-sensitive error text with the provider rather than exposing the URL.
The subscription update fails: check that the computer is online, the URL is complete, and the profile has not been disabled or replaced. A temporary server or provider-side issue can also prevent an update. Try again after checking the provider’s service information, but avoid repeatedly changing the URL or deleting a working profile before you have recorded its settings. If the link has expired or been revoked, only the provider can issue a valid replacement.
Windows denies a permission request: check which feature triggered the prompt. A virtual network interface or driver may require administrator approval; a basic profile import generally does not need the same network-level permission. If you trust the app source and want to use that feature, sign in with an authorized Windows account or ask the device administrator. If the device is managed, do not attempt to override its policy.
The app says connected, but a test page shows the usual result: confirm that the intended profile and server are active, then check whether the browser is using the system proxy. Temporarily compare rule mode with global mode if appropriate, and verify that another proxy extension is not controlling browser traffic. If the IP changes in one browser but not another, investigate each browser’s proxy and DNS settings rather than reinstalling the client immediately.
Some apps work while others do not: this often points to different proxy support or routing rules, not necessarily a failed subscription. Review whether the profile sends the destination direct, whether the application honors Windows proxy settings, and whether TUN mode is required for that app. TUN can affect system traffic more broadly, so consider firewall prompts and existing VPN clients before enabling it. If you switch modes, test and then return to the previous setting if the result gets worse.
Internet access stops after disconnecting: check whether Windows still has a manual proxy configured or whether another client has changed the network route. Turn off the proxy setting in Clash Verge, close the app normally, and inspect Windows proxy settings before changing unrelated network adapters. If you previously enabled a virtual interface, use the app’s own control to disable it first. Avoid deleting drivers or resetting all network settings as an early troubleshooting step.
A reliable setup is one you can explain and reproduce: you know which profile is active, which route is selected, what mode is handling traffic, and how you tested the result. Keep the subscription URL private, update the profile using the provider’s instructions, and restore Windows settings if you stop using the client. These habits make routine troubleshooting clearer without relying on a single “connected” label.