ClashX Pro System Proxy Setup on macOS: How to Enable
Learn how to turn on the macOS system proxy in ClashX Pro, choose the right proxy mode, and disable it when needed. The guide uses clear menu paths and practical checks so beginners can confirm that supported browsers and applications are routing through their selected ClashX Pro node.
What the ClashX Pro System Proxy Actually Does
ClashX Pro's system proxy switch connects macOS network settings to the local proxy service exposed by ClashX Pro. When the switch is enabled, macOS usually writes an HTTP proxy and an HTTPS proxy entry for the active network service, pointing them to a local address such as 127.0.0.1:7890. Applications that respect the macOS proxy configuration can then send supported web traffic through the proxy group selected in ClashX Pro.
This is different from a full system tunnel. System proxy mode does not automatically capture every packet, every DNS request, or every application. Browsers and command-line tools often support the macOS proxy settings, while some games, update services, virtual machines, and applications with their own network stack may ignore them. If you need broader traffic capture, use a supported TUN feature in a maintained Clash-compatible client instead of assuming that the system proxy switch covers everything.
There are three separate choices to make before testing. First, ClashX Pro must have a valid configuration and at least one usable proxy node. Second, its proxy mode must be selected correctly. Third, the macOS system proxy must be enabled for the network service that is currently carrying traffic. Turning on only one of these does not guarantee that a browser request will use the selected node.
System Proxy Is an Application-Level Path
Use system proxy mode for browsers and applications that follow macOS network settings. Do not treat the switch as a VPN replacement. If an application bypasses system proxy settings, its traffic may continue to use the direct network even while Safari or another supported browser is proxied.
Prepare ClashX Pro Before Enabling the Switch
Before changing macOS settings, open ClashX Pro from the menu bar and confirm that the client is running normally. The menu bar icon should be present, and the configuration should contain proxy groups or nodes rather than only an empty profile. If the profile has not been imported, use the provider's subscription URL or a local configuration file first, then wait for the proxies and rules to finish loading.
Check the configuration's local ports in the ClashX Pro preferences. Common defaults are 7890 for HTTP and mixed traffic and 7891 for SOCKS5, but these values are not universal. A changed port, another application already using the port, or a client configured to expose only one protocol can make the system proxy appear enabled while connections still fail. Always use the port shown in the current ClashX Pro settings instead of copying a number from another guide.
| Item | What to confirm | Why it matters |
|---|---|---|
| Configuration | A profile is loaded and its proxies are visible | The system proxy has nothing useful to forward without a loaded profile |
| Proxy group | A node or group can be selected in the ClashX Pro menu | Rule mode still needs a working proxy outbound for matched traffic |
| Local port | HTTP, mixed, or SOCKS port matches the client settings | macOS must connect to the port where ClashX Pro is listening |
| Mode | Rule, Global, or Direct is intentionally selected | The mode determines whether a request uses rules, a proxy, or a direct path |
| Connectivity | The selected node passes a connection test or loads a known target | A system proxy cannot repair an unavailable or expired node |
Pay attention to the active macOS network interface as well. A Mac can have Wi-Fi, Ethernet, a USB adapter, and a VPN service listed at the same time. The system proxy may be enabled for Wi-Fi while the actual connection is using Ethernet. In that case, browser traffic can look direct even though the ClashX Pro switch is visibly on.
Choose the Right ClashX Pro Proxy Mode
ClashX Pro normally exposes three practical modes: Rule, Global, and Direct. The exact wording can vary slightly by release, but the behavior is the same. Select the mode before testing the system proxy so that a successful connection proves the path you actually intend to use.
| Mode | Traffic decision | Best use | Common misunderstanding |
|---|---|---|---|
| Rule | Each request follows the configuration's rule list | Everyday use with direct domestic services and proxied matched domains | A proxy group must still be selected; rules do not create a node automatically |
| Global | Requests accepted by the system proxy use the selected proxy group | Short troubleshooting sessions or testing a specific node | Applications that ignore system proxy settings remain outside the path |
| Direct | Requests are sent directly whenever the client handles them | Temporarily comparing direct and proxied behavior | It can make a healthy node look broken because the node is intentionally bypassed |
Rule Mode for Normal Daily Use
Rule mode is usually the most practical default. The configuration decides whether a domain uses DIRECT, a proxy group, or another outbound. It preserves direct access for services that should remain local while sending matched destinations through the selected group. When diagnosing a problem, inspect the ClashX Pro connection log and check the rule result for the exact domain instead of assuming that every page should use the proxy.
Global Mode for a Clear Test
Global mode is useful when you want one simple test: a supported application should connect through the selected proxy group. Choose a known working node or group, enable global mode, and then open a fresh browser window. If the result is still direct, the problem is probably the macOS proxy binding, a browser-level override, a stale connection, or an application that does not honor system settings rather than the rule list itself.
Direct Mode as a Comparison
Direct mode is valuable as a control test. With the system proxy still enabled, switch between Direct and Global and compare the connection log and external address. If both tests produce exactly the same result, check whether the browser is bypassing the proxy or whether the macOS network service has no proxy entry. Do not use Direct mode as the final setting when the purpose is to route selected traffic through ClashX Pro.
How to Enable the macOS System Proxy in ClashX Pro
The menu label can differ between ClashX Pro builds, but the switch is commonly named Set as system proxy or Set as Proxy. The following sequence separates client configuration from the macOS verification step, which makes it easier to identify where a failure occurs.
- Launch ClashX Pro and leave it running in the macOS menu bar. If macOS blocks the first launch, open System Settings › Privacy & Security and approve the application according to the prompt before continuing.
- Open the ClashX Pro menu from the menu bar icon and select the intended configuration or profile. Wait until its proxy groups and rules are available.
- Choose Mode › Rule for normal split routing, or choose Mode › Global for a short, unambiguous proxy test. Select a working node or proxy group if the menu provides that option.
- Return to the ClashX Pro menu and click Set as system proxy. The menu item should show a check mark or another active state after the change.
- Open System Settings › Network, select the interface currently in use, and open Details › Proxies. Confirm that the HTTP proxy and HTTPS proxy entries point to a local address such as
127.0.0.1with the port displayed in ClashX Pro. - Click OK or Apply if macOS presents that button. Then close and reopen the browser, because existing connections and persistent HTTP sessions may continue using the old route.
- Open a test page and inspect the ClashX Pro connection log at the same time. Look for the requested domain, the matched rule, and the outbound proxy group. A page loading by itself is not enough evidence that it used the intended node.
Check the Active Network Service
If Wi-Fi and Ethernet are both connected, macOS may apply the proxy to only one service. Verify the interface carrying the default route, then inspect that service's proxy entries. A checked ClashX Pro menu item does not always tell you which macOS network service was modified.
For a controlled test, first record the result in Direct mode, then switch to Global mode and select a known working node. Open a private browser window, visit the same test destination, and compare the external address or the connection log. Finally, switch back to Rule mode and verify that a domain expected to be direct and a domain expected to be proxied are handled by their respective outbounds.
Verify Browsers and Applications Are Using the Proxy
Verification should happen at two levels: the macOS settings level and the ClashX Pro traffic level. The first confirms that macOS has a proxy address configured. The second confirms that a real application request reached ClashX Pro and was assigned an outbound. Checking only the menu icon can miss a wrong port, a stale profile, or a browser exception.
- Check the macOS entry. Go to System Settings › Network › active interface › Details › Proxies. Confirm that the HTTP and HTTPS proxy fields contain the local host and the correct port. If the fields are empty, the ClashX Pro switch did not write the settings to that service.
- Check the ClashX Pro log. Load a new page and search the log for its domain. The entry should show the connection, the matched rule, and the selected outbound. If no entry appears, that application request did not pass through ClashX Pro.
- Check the browser configuration. Safari normally follows macOS proxy settings. Chromium-based browsers generally inherit system proxy settings unless a command-line flag, extension, enterprise policy, or separate proxy manager changes the behavior. Firefox may use its own proxy setting, so inspect Settings › Network Settings if it does not appear in the ClashX Pro log.
- Check command-line behavior. Tools such as
curlmay honor environment variables such asHTTP_PROXYandHTTPS_PROXY, but they are not a universal substitute for macOS system proxy settings. Test explicitly with the local HTTP proxy when needed, for examplecurl -x http://127.0.0.1:7890 https://example.com, replacing the port with the value shown in ClashX Pro. - Check the application type. A browser page using the proxy does not prove that a game launcher, Git client, virtual machine, Docker workload, or background updater uses it. These programs may have independent proxy fields or may require a TUN-based solution.
| Observation | Likely explanation | Next check |
|---|---|---|
| macOS proxy fields are empty | The switch is off or applied to another network service | Enable it again and inspect the active interface |
| Proxy fields are correct, but the Clash log is empty | The application is bypassing the system proxy | Inspect its own proxy settings or test Safari |
| The log shows a connection but it uses DIRECT | Rule mode matched a direct rule or Direct mode is selected | Review the mode, rule order, and selected group |
| The log shows a proxy error or timeout | The node, group, port, or upstream connection is failing | Test another node and confirm the local port |
| Only an already-open tab behaves differently | The browser reused an existing connection or cached result | Open a new window, clear the session, or restart the browser |
Fix Common ClashX Pro System Proxy Problems
Most setup failures are caused by a mismatch between the client port and the macOS entry, a proxy applied to the wrong network service, or an application that does not use the system proxy. Work through the checks in a fixed order instead of changing several settings at once.
The Proxy Is Enabled but Pages Do Not Load
Open ClashX Pro's preferences and record the HTTP or mixed port. Compare it with the HTTP and HTTPS fields under the active macOS network service. A common mistake is entering the SOCKS5 port into an HTTP proxy field or using a previous default such as 7890 after the client was changed to another port. Correct the entry, apply the macOS settings, and retry with a fresh browser window.
The Node Works but the Browser Uses a Direct Route
Switch temporarily to Global mode and select the node directly. If the log now shows the expected outbound, Rule mode is working as configured and the original domain probably matched a DIRECT rule. Review the rule order: the first matching rule wins, so a broad domain, geosite, IP, or final MATCH rule can determine the result before a later rule is considered.
The Address Looks Unchanged After Switching Modes
DNS caching and persistent connections can make a mode change look ineffective. Quit and reopen the browser, test in a private window, and inspect a fresh request in the ClashX Pro log. System proxy mode alone also does not guarantee that every DNS lookup uses the proxy. If the goal is full DNS interception or system-wide traffic capture, evaluate the client's TUN and DNS configuration separately rather than expecting the HTTP proxy switch to provide it.
Another VPN or Proxy Tool Is Also Running
Disable other VPN clients, menu-bar proxy utilities, browser extensions, and shell proxy variables while testing. Two tools can compete for the same local port or repeatedly overwrite macOS proxy settings. After the test succeeds, re-enable other tools one at a time and check the ClashX Pro log after each change.
Do Not Diagnose from the Menu Icon Alone
A checked system proxy item proves only that ClashX Pro requested a macOS proxy change. It does not prove that the active interface has the right port, that the browser accepted the setting, or that the selected node completed the connection. Always pair the menu state with the macOS proxy panel and a ClashX Pro log entry.
How to Disable the System Proxy Cleanly
When you no longer need the proxy, open the ClashX Pro menu and click Set as system proxy again to remove the active check mark. Then open System Settings › Network › active interface › Details › Proxies and confirm that the HTTP and HTTPS proxy fields are cleared or returned to the values required by your network. If multiple services were configured, inspect Wi-Fi and Ethernet separately.
Disabling the system proxy does not necessarily stop ClashX Pro, disconnect an independent TUN service, or remove browser-specific proxy settings. If a browser continues to use the proxy, check its own network settings and restart it. If command-line requests remain proxied, inspect HTTP_PROXY, HTTPS_PROXY, and ALL_PROXY in the current shell. A clean comparison should show no new request in the ClashX Pro log after the browser is restarted.
- Turn off the ClashX Pro system proxy switch.
- Verify the active macOS network service has no unintended HTTP or HTTPS proxy entry.
- Disable TUN or other traffic-capture features separately if they were enabled.
- Remove temporary browser proxy settings or extensions used for testing.
- Restart applications that keep persistent network connections, then perform one direct connection test.
A Reliable ClashX Pro Setup Checklist
A dependable macOS system proxy setup follows a short but specific sequence: load a valid profile, confirm the local port, select Rule or Global mode intentionally, enable the system proxy from the ClashX Pro menu, and verify the active macOS network service. After that, confirm a real request in the ClashX Pro log rather than relying only on a page loading or a menu check mark.
Use Rule mode for normal split routing, Global mode when testing a particular node, and Direct mode only as a comparison. Remember that system proxy mode covers applications that honor macOS proxy settings, not every process on the computer. When an application bypasses the system proxy or when DNS and non-HTTP traffic must also be captured, investigate its own proxy options or use an appropriate TUN configuration.
Continue With the Client Setup
Install a compatible client or review the basic configuration workflow before importing profiles and testing system-wide behavior.