TUN mode takes its name from TUN, a virtual network interface that hands IP packets to a program instead of a network card. A proxy client that turns it on becomes the route for the machine's traffic: every TCP and UDP connection, from every app, arrives at the client, which applies its rules and sends each connection to a proxy or straight to the internet. Clash Verge is one desktop client with a TUN mode switch.
TUN mode vs system proxy
The alternative is the system proxy, a single operating system setting that apps may read. Clash Verge's documentation spells out the difference:
| System proxy | TUN mode | |
|---|---|---|
| Apps that ignore proxy settings | Missed | Captured |
| UDP | Not carried | Captured |
| Privileges | None extra | Administrator rights, or a service installed once, plus the core allowed through the firewall |
So TUN mode is the answer when a program has no proxy setting and ignores the system one. It does not depend on how the program was built, which is where a preload tool like ProxyChains falls short with static binaries. System proxy vs TUN mode vs per-app rules compares the options in full.
What it does not change
- The node still decides what it can carry. TUN mode captures UDP, but an HTTP proxy cannot relay it and a SOCKS5 proxy only does where both ends support UDP relay. In a test on the Mihomo core, UDP matched to a node that could not carry it fell through to the next rule and left directly.
- Rules still decide. TUN mode changes what the client sees, not where it sends it. That is rule-based routing.
- It is not a VPN. The adapter is the same kind a VPN client creates, but the tunnel ends in the proxy client on your own machine. Proxy vs VPN covers the difference.
The same idea on a server
On a Linux machine without a desktop client, Redsocks gets a similar result with firewall redirect rules instead of a virtual adapter. It carries TCP only.
Common confusion
TUN and TAP are siblings: a TAP device carries Ethernet frames, a TUN device carries IP packets. Proxy clients use TUN, because they only care about connections, not the link layer underneath.