开源 · 跨平台 · 智能分流 Open Source · Cross-Platform · Smart Routing

Clash – 跨平台智能分流代理工具 Clash – Cross-Platform Smart Routing Proxy

支持多协议、多平台,基于规则自动分流。开源、安全、高性能,让网络访问更智能、更自由。 Multi-protocol, multi-platform, rule-based automatic traffic routing. Open source, secure, high-performance — smarter internet access for everyone.

最新版本Latest: v0.20.39 GPL-3.0

为什么选择 Clash? Why Clash?

六大核心能力,重新定义代理工具的使用体验。 Six core capabilities that redefine the proxy tool experience.

多协议兼容Multi-Protocol

支持 Shadowsocks(R)、VMess、Trojan、Snell、SOCKS5、WireGuard 等主流协议,一个工具覆盖所有需求。Supports Shadowsocks(R), VMess, Trojan, Snell, SOCKS5, WireGuard and more — all in one tool.

智能分流Smart Routing

基于域名、IP、进程名等规则自动分流,直连与代理路径分离,兼顾速度与稳定。Rule-based routing by domain, IP, and process name. Direct and proxy paths separated for optimal speed and stability.

策略组管理Strategy Groups

支持 fallback、load balance、url-test 等自动化策略组,智能切换最优节点。Auto strategy groups with fallback, load balance, and url-test for intelligent node switching.

Fake-IP DNSFake-IP DNS

减少 DNS 污染影响,提升网络性能与解析速度,让连接更快更稳定。Mitigates DNS poisoning, boosts resolution speed and network performance for faster, more stable connections.

跨平台支持Cross-Platform

Windows / macOS / Linux / Android / iOS / OpenWrt 全覆盖,随时随地使用。Full coverage across Windows, macOS, Linux, Android, iOS, and OpenWrt — use anywhere, anytime.

透明代理Transparent Proxy

自动路由表管理、Redirect TCP、TProxy TCP/UDP,无缝接管系统流量。Auto route table management with Redirect TCP and TProxy TCP/UDP for seamless system-wide traffic control.

远程 ProvidersRemote Providers

动态加载远程代理列表与规则集,配置自动更新,省去手动维护的麻烦。Dynamically load remote proxy lists and rule sets with auto-updating configs — no manual maintenance needed.

RESTful APIRESTful API

通过全面 API 实现配置就地更新与自动化管理,开发者友好。Comprehensive API for in-place config updates and automation — developer-friendly to the core.

选择您的平台 Choose Your Platform

覆盖主流操作系统,选择对应版本开始使用。 Available for all major operating systems. Pick your version and get started.

Windows

v0.20.39

配置简单,适合新手使用Easy setup, perfect for beginners

官方下载Download

macOS

v1.123.0

Mac 系统上使用最多的 Clash 客户端Most popular Clash client for Mac

官方下载Download

Android

v2.5.12

安卓平台官方 Clash 客户端Official Clash client for Android

官方下载Download

iOS

暂无官方版本,推荐使用 Shadowrocket 作为替代No official version; Shadowrocket recommended

查看替代方案See Alternatives

OpenWrt

OpenClash 路由器插件OpenClash router plugin

GitHub 下载GitHub

三步开始使用 Clash Get Started in 3 Steps

无需复杂配置,跟随引导即可快速上手。 No complicated setup needed. Follow the guide and get running quickly.

下载安装Download & Install

选择对应系统版本下载并安装,优先使用官方或可信来源,避免安全风险与捆绑软件,确保从正规渠道获取安装包。Choose the version for your OS and install it. Always use official or trusted sources to avoid security risks and bundled malware.

导入配置Import Config

通过订阅链接或本地 YAML 文件导入配置,按需启用规则集与策略组,支持远程自动更新,无需反复手动调整。Import config via subscription link or local YAML file. Enable rule sets and strategy groups as needed with remote auto-update support.

启用代理Enable Proxy

开启系统代理或服务模式,检查分流是否生效;根据网络环境切换模式与节点,访问测试网站确认一切正常运行。Turn on system proxy or service mode, verify that routing rules are working, and switch modes/nodes based on your network environment.

我们重视您的隐私 We Value Your Privacy

Clash 以开源透明为基石,确保您的数据始终由您掌控。 Built on open-source transparency, Clash ensures your data stays under your control.

开源透明Open Source

以开源社区与衍生客户端为主,核心代码公开可审计,任何人都能查看、审查和贡献代码,杜绝后门隐患。Core code is publicly auditable. Anyone can review and contribute, eliminating backdoor concerns entirely.

数据本地化Local Data

配置与日志保存在本地设备,不上传云端,您的浏览记录和网络数据始终留在您自己的设备上。Configs and logs stay on your local device — no cloud uploads. Your browsing data remains yours alone.

加密传输Encrypted Transport

优先使用 TLS 等加密方式,保障传输安全,确保数据在传输过程中不会被第三方窃取或篡改。Prioritizes TLS and other encryption methods to secure data in transit against interception and tampering.

安全建议:Security Tips: 请仔细审查订阅来源,优先使用可信服务商;定期更新客户端与规则集以获取最新安全修复。 Always verify subscription sources and use trusted providers. Keep your client and rule sets updated for the latest security patches.

您可能想问的 Frequently Asked Questions

以下是关于 Clash 的常见疑问,点击问题查看详细解答。 Common questions about Clash. Click to expand detailed answers.

Clash 是一款跨平台网络代理工具,支持多种代理协议(V2Ray、Shadowsocks、Trojan 等),主要用于提升网络访问体验。以下是详细说明: Clash is a cross-platform network proxy tool supporting multiple protocols (V2Ray, Shadowsocks, Trojan, etc.), designed to enhance internet access experience. Here's a detailed breakdown:

  1. 核心定位:Clash 是一个基于规则的网络代理核心,在网络层和应用层运行,不同于传统 VPN 的全局隧道模式。Core Positioning: Clash is a rule-based proxy core operating at both network and application layers, fundamentally different from traditional VPN tunnel modes.
  2. 协议支持:兼容 Shadowsocks、ShadowsocksR、VMess、Trojan、Snell、SOCKS5、WireGuard 等多种主流代理协议,一个工具满足所有需求。Protocol Support: Compatible with Shadowsocks, ShadowsocksR, VMess, Trojan, Snell, SOCKS5, WireGuard and more — all in one tool.
  3. 运行机制:通过解析配置文件中的规则,对不同的网络请求进行智能分流——国内网站直连、国外网站走代理,实现按需代理而非全局代理。How It Works: Parses configuration rules to intelligently route different network requests — direct connection for domestic sites, proxy for international ones.
  4. 平台覆盖:支持 Windows、macOS、Linux、Android、iOS、OpenWrt 等主流操作系统,覆盖桌面端、移动端和路由器设备。Platform Coverage: Supports Windows, macOS, Linux, Android, iOS, OpenWrt — covering desktops, mobile devices, and routers.
  5. 开源许可:基于 GPL-3.0 开源许可证发布,核心代码公开透明,社区活跃,任何人都可以审查和贡献代码。License: Released under GPL-3.0 open-source license with publicly auditable core code and an active community.
  6. 适用场景:适合需要精细化网络管理的用户,无论是日常浏览、开发调试还是网络优化,Clash 都能提供灵活的解决方案。Use Cases: Ideal for users needing granular network management — from daily browsing and development debugging to network optimization.

核心区别在于"按规则分流"而非"全局隧道"。传统 VPN 将所有流量通过加密隧道发送,而 Clash 允许对不同域名、IP、应用指定不同策略。以下是具体对比: The key difference is rule-based routing vs. global tunneling. Traditional VPNs send all traffic through an encrypted tunnel, while Clash lets you specify different strategies per domain, IP, or application:

  1. 流量处理方式:传统 VPN 是全局代理,所有流量都经过 VPN 服务器;Clash 按规则分流,国内流量直连、国外流量走代理,兼顾速度与访问需求。Traffic Handling: Traditional VPNs proxy all traffic; Clash routes by rules — domestic direct, international via proxy for optimal speed.
  2. 灵活度对比:VPN 通常只有"开/关"两种状态;Clash 支持策略组、负载均衡、自动故障转移等高级功能,灵活度远超传统方案。Flexibility: VPNs typically offer only on/off; Clash supports strategy groups, load balancing, auto failover — far more flexible.
  3. 性能影响:VPN 全局代理可能导致国内网站访问变慢;Clash 的智能分流确保国内直连不受影响,仅在需要时使用代理。Performance: Global VPN proxy can slow domestic sites; Clash's smart routing ensures direct connections remain unaffected.
  4. 配置粒度:Clash 支持基于域名、IP 段、进程名、应用等多维度规则配置,精细程度远超传统 VPN 的单一设置。Configuration Granularity: Clash supports rules by domain, IP range, process name, and app — far more granular than VPN single settings.
  5. 生态开放性:Clash 开源且支持第三方客户端和远程规则集,社区生态丰富;传统 VPN 多为闭源商业产品,扩展性有限。Ecosystem: Clash is open-source with third-party clients and remote rule sets; most VPNs are closed-source with limited extensibility.

只需几个简单步骤即可完成从安装到使用的全过程。以下是完整的入门流程,适合没有任何技术背景的新用户: Just a few simple steps from installation to full use. Here's the complete beginner-friendly walkthrough:

  1. 选择客户端:根据您的操作系统选择对应版本——Windows 用户下载 Clash for Windows,macOS 用户使用 ClashX,Android 用户安装 Clash for Android。Choose Client: Pick the version for your OS — Clash for Windows, ClashX for macOS, or Clash for Android for mobile.
  2. 下载并安装:从官方 GitHub 发布页或可信来源下载安装包,完成安装后启动客户端,首次运行可能需要授予网络权限。Download & Install: Get the installer from the official GitHub releases page or trusted sources, then launch the client and grant network permissions.
  3. 获取订阅链接:从您的代理服务商处获取订阅链接(通常以 URL 形式提供),这是自动配置节点和规则的关键凭证。Get Subscription Link: Obtain a subscription link from your proxy provider — this is the key credential for auto-configuring nodes and rules.
  4. 导入配置:在客户端的 Profiles 或配置页面中,选择"新增订阅",粘贴订阅链接并保存,客户端将自动下载并应用节点和规则集。Import Config: In the client's Profiles page, add a new subscription, paste the link, save — the client auto-downloads and applies nodes and rules.
  5. 选择策略与节点:在代理页面中选择合适的策略组和节点,通常建议选择"自动选择"或延迟最低的节点以获得最佳体验。Select Strategy & Node: Choose an appropriate strategy group and node — "auto-select" or lowest-latency node is recommended for the best experience.
  6. 开启系统代理:点击"开启系统代理"或类似按钮,然后访问一个测试网站确认分流是否生效。如遇问题可切换节点或检查规则配置。Enable System Proxy: Click "Enable System Proxy" and visit a test site to verify routing is working. Switch nodes or check rules if issues arise.

订阅链接是自动更新节点列表与规则的核心机制。它让您无需手动维护配置,节点变更时自动同步。以下是详细使用方法: A subscription link is the core mechanism for auto-updating node lists and rules. It eliminates manual config maintenance with automatic sync:

  1. 定义说明:订阅链接是一个由服务商提供的特殊 URL,包含了加密的节点信息和规则集数据,客户端通过访问该链接获取最新配置。Definition: A subscription link is a special URL provided by your service provider containing encrypted node info and rule set data for client retrieval.
  2. 获取途径:通常在您购买代理服务后,服务商会在用户面板或欢迎邮件中提供订阅链接,请妥善保管不要泄露给他人。Where to Get: Usually provided in the user dashboard or welcome email after purchasing proxy service — keep it safe and private.
  3. 添加方法:打开 Clash 客户端,进入 Profiles(配置)页面,点击"新增订阅"或"New Profile",在弹出的输入框中粘贴订阅链接。How to Add: Open Clash client, go to Profiles page, click "New Profile", and paste the subscription link in the input field.
  4. 保存与更新:为订阅配置命名后点击保存,然后点击"更新"按钮,客户端将从链接地址拉取最新的节点列表和规则集。Save & Update: Name your subscription, save it, then click "Update" — the client will fetch the latest node list and rule sets from the link.
  5. 自动更新设置:建议在设置中开启自动定期更新(如每24小时更新一次),确保节点信息和规则始终处于最新状态。Auto-Update: Enable periodic auto-update in settings (e.g., every 24 hours) to keep node info and rules up to date automatically.
  6. 常见问题排查:如果更新失败,请检查订阅链接是否过期、网络是否通畅,或联系服务商确认订阅地址是否有效。Troubleshooting: If update fails, check if the link has expired, verify network connectivity, or contact your provider to confirm the subscription URL is valid.

Clash Premium 版本在开源核心基础上增加了多项高级网络功能。这些功能主要面向需要更强大网络管理能力的进阶用户,以下是详细说明: Clash Premium adds several advanced networking features on top of the open-source core. These are aimed at power users needing more robust network management:

  1. TUN 设备支持:Premium 版本支持创建虚拟 TUN 网络设备,可以在系统层面接管所有网络流量,实现真正的全局透明代理,无需逐个应用设置代理。TUN Device: Premium supports creating virtual TUN network devices to handle all system traffic at the OS level for true global transparent proxy.
  2. WireGuard 集成:原生支持 WireGuard 协议,这是一种现代、高性能的 VPN 协议,具有更低的延迟和更高的吞吐量表现。WireGuard Integration: Native support for the WireGuard protocol — a modern, high-performance VPN protocol with lower latency and higher throughput.
  3. 自动路由表管理:系统自动管理路由表规则,无需用户手动配置复杂的网络路由,大幅降低透明代理的使用门槛。Auto Route Table: Automatic route table management eliminates the need for manual complex network route configuration, greatly simplifying transparent proxy setup.
  4. Redirect TCP 模式:支持 TCP 重定向功能,可以将经过网关的 TCP 流量自动引导至代理通道,适用于路由器等网关设备场景。Redirect TCP: Supports TCP redirection to automatically route gateway TCP traffic through the proxy channel — ideal for router and gateway scenarios.
  5. TProxy TCP/UDP:支持透明代理 TCP 和 UDP 流量,实现对全部网络协议的无缝接管,包括 DNS 查询、游戏流量等 UDP 密集型应用。TProxy TCP/UDP: Transparent proxy for both TCP and UDP traffic, enabling seamless handling of all protocols including DNS queries and UDP-heavy applications like gaming.
  6. 适用人群:Premium 功能主要面向需要在路由器、网关或复杂网络环境中部署 Clash 的高级用户和网络管理员。Target Users: Premium features are primarily for advanced users and network administrators deploying Clash in routers, gateways, or complex network environments.

Clash 通过开源透明、数据本地化和加密传输三重机制保障用户隐私。以下是其在安全方面的具体措施和用户应注意的事项: Clash protects user privacy through open-source transparency, local data storage, and encrypted transport. Here are the specific security measures and user considerations:

  1. 开源可审计:核心代码在 GitHub 上公开,全球开发者可以审查每一行代码,从根本上杜绝了后门和恶意功能的可能性,这是闭源软件无法比拟的安全优势。Open Source Auditable: Core code is public on GitHub for global developer review, fundamentally eliminating backdoor and malware possibilities — a security advantage closed-source software cannot match.
  2. 本地数据存储:所有配置信息、日志文件和规则集均保存在用户本地设备上,不会自动上传至任何云端服务器,用户对自己的数据拥有完全控制权。Local Data Storage: All configs, logs, and rule sets are stored locally — never auto-uploaded to any cloud server. You have full control over your data.
  3. 加密传输保障:Clash 优先采用 TLS 等业界标准加密协议进行数据传输,确保网络流量在传输过程中不被第三方窃听或篡改,保障通信内容的机密性和完整性。Encrypted Transport: Clash prioritizes TLS and other industry-standard encryption protocols to protect data in transit from interception and tampering.
  4. 订阅来源审查:用户应仔细验证订阅链接的来源可靠性,避免使用来路不明的免费订阅,因为恶意订阅可能包含不当规则或导向不安全的节点。Subscription Vetting: Users should carefully verify subscription sources and avoid unknown free subscriptions, which may contain malicious rules or unsafe nodes.
  5. 定期更新建议:保持客户端和规则集更新至最新版本,以及时获取社区发现并修复的安全漏洞补丁,这是维护长期安全的关键习惯。Update Regularly: Keep the client and rule sets updated to receive the latest security patches — a critical habit for long-term security maintenance.
  6. 社区安全生态:活跃的开源社区能快速发现和响应安全问题,用户可以通过 GitHub Issues 等渠道报告漏洞并获得及时的修复支持。Community Security: An active open-source community quickly identifies and responds to security issues — report vulnerabilities via GitHub Issues for timely fixes.