Updated July 2026 · 6 min read
Windows Firewall and antivirus rules
When TUN mode or LAN sharing fails, the cause is often not a bad config — it is the firewall prompt that got dismissed the first time around.
What to choose on first run
Windows raises a network access prompt when the service is installed or TUN starts for the first time. Tick private, and decide on public separately — most people do not want to share a proxy on a cafe hotspot.
That prompt sometimes appears behind other windows and disappears on its own after a few seconds. Nothing looks wrong in the client afterwards; things simply never connect.
Fixing a wrong answer
Open "Allow an app or feature through Windows Defender Firewall", find the client and its service component in the list, and tick the private network column.
If the entry is not in the list at all, the rule was recorded as a block. Delete the related inbound rules and start the program again so it asks for permission from scratch.
Tick the private network box in that prompt. Allowing only public networks leaves devices behind your home router unable to connect.
LAN sharing needs one more step
Turning on "allow LAN" only makes the core willing to listen on every interface. Without a matching firewall rule, other devices still cannot reach the proxy port.
While you are there, check how Windows classifies the current network. It sometimes labels a home Wi-Fi as public, and your private-network rule then does nothing.
Third-party security software
Blocking service-mode installation is the most common case: the service will not install, or it vanishes right after. Allow it during that step and restore protection afterwards.
Do not whitelist a whole drive to save time. An exception for the specific program folder is enough, and a narrower scope is a safer one.
What is the project?
Clash Verge Rev is a Tauri-based GUI for Mihomo with profile management, system proxy, TUN mode, rule editing and WebDAV backups.