Welcome to Univista — we're glad you're here. If anything's unclear, open Help or reach us via support on this site and we'll help you get connected.

TUN Mode vs System Proxy: Which to Use (When the Browser Works but an App Won't)

Updated

Diagram: system proxy only captures proxy-aware apps; TUN captures every app at the IP layer
Diagram: system proxy only captures proxy-aware apps; TUN captures every app at the IP layer

What is a system proxy?

A system proxy is an operating-system switch that tells apps to send their HTTP/SOCKS traffic to a local proxy port. Only proxy-aware apps honour it — browsers almost always do, which is why web pages usually work the moment you set it. But many command-line tools, some games, and certain apps (some Telegram builds, dev/terminal tools) ignore the system proxy and connect directly, bypassing it — that's the classic cause of "the browser works but this one app won't connect." A system proxy needs no virtual adapter, is lightweight, and rarely disturbs other software.

What is TUN mode?

TUN mode creates a virtual network adapter (a TUN device) that captures all of the machine's traffic at the IP layer, like a real VPN tunnel. Whether or not an app understands proxy settings, its traffic is routed through the tunnel. The trade-off: it needs VPN / network-extension permission (on phones this shows up as "add a VPN configuration"; on desktop it sometimes needs admin rights), and usually only one TUN-style app can own the adapter at a time, so it can clash with the built-in VPN or another client.

The key differences

Which one to choose (one-line rule)

Only browsing the web: a system proxy is enough — lighter, less disruptive to other software, and no VPN permission needed. An app ignores the proxy (Telegram, games, dev/terminal tools won't connect), or you want whole-device coverage: switch to TUN mode. Remember the classic symptom — "browser opens, app won't" almost always means turn on TUN. Conversely, if TUN slows the whole machine down or fights your company VPN, fall back to a system proxy for the browser only.

How to use this on Univista

  1. Import your subscription, pick a low-latency healthy node, and test web pages in the default mode first.
  2. If only one app fails while web pages work, switch the client's connection mode from "system proxy / rule" to "TUN / virtual adapter" and retry.
  3. On desktop, TUN may prompt for admin rights; on mobile it pops "add a VPN configuration" — allow it.
  4. With TUN on, keep only one client owning the adapter and close other VPN/TUN apps, or they fight over it and all drop.
  5. Per-platform steps: iOS and Android; protocol background: What is VLESS Reality.

FAQ

What's the difference between TUN mode and a system proxy?
A system proxy only routes proxy-aware apps (mostly browsers); other apps connect directly and bypass it. TUN mode builds a virtual adapter that captures all of the machine's traffic at the IP layer, so every app enters the tunnel whether or not it understands proxies.
Should I use TUN or a system proxy?
For web-only use, a system proxy is enough and needs no VPN permission. If an app ignores the proxy and won't connect, or you want whole-device coverage, use TUN.
Why does the browser open but an app won't connect?
Usually because that app ignores the system proxy and connects directly, so it fails under system-proxy mode. Switching to TUN routes the whole machine through the tunnel and typically fixes it.
Is TUN mode slower or heavier on battery?
TUN adds a virtual adapter and routing layer, so some devices see slightly more battery use or latency, but the difference is usually small — in exchange you get whole-app coverage and fewer leaks.
Do I still need a system proxy when TUN is on?
Usually not. TUN already captures all traffic; running both can interfere. Pick one per your client's guidance.
Why did my other VPN drop after I enabled TUN?
Only one app can own the TUN adapter at a time. Keep a single client and close other VPN/TUN apps.
Can a system proxy leak my real IP?
Apps that ignore the system proxy connect directly and expose your real exit. If that worries you, use TUN so all traffic goes through the tunnel.
In Clash Verge / Clash for Windows, where are the TUN and system-proxy switches, and which should I turn on?
Both clients expose "System Proxy" and "TUN Mode" as two <strong>independent toggles</strong>: Clash Verge (including Clash Verge Rev / the Clash Meta core) has separate "System Proxy" and "TUN Mode" switches in the sidebar or Settings; Clash for Windows has "System Proxy" and "TUN Mode" on the General tab. For everyday browsing just turn on "System Proxy"; if an app bypasses the proxy and won't connect, also enable "TUN Mode" (the first time you enable TUN it usually installs a service or asks for admin rights). You don't need both — pick one for the job.
What about desktop clients like v2rayN, Nekoray/Nekobox?
v2rayN (Windows) has the several "system proxy" states plus a "Tun mode" toggle in its menu — TUN needs its tun service installed once. Nekoray/Nekobox desktop: tick "TUN Mode" (needs admin), or leave it off and use "Set system proxy". The rule is the same as any client — system proxy for browser-only, switch to TUN when an app bypasses it.
On phones (Shadowrocket / Stash / Surge on iOS, Nekobox / v2rayNG / Happ on Android), is there even a TUN vs system-proxy choice?
Mostly no — <strong>mobile clients are almost always TUN-style</strong>. These iOS/Android apps work through the system "VPN / network extension", so turning one on already builds a tunnel that captures the whole device (iOS pops up "Add VPN configuration"); there's no separate "system proxy" switch like on desktop. So "TUN or system proxy" is mainly a <strong>desktop (Windows / macOS)</strong> question — on a phone you just allow the VPN profile and pick a healthy node.
Using another provider? Univista is faster on Reality. See why

Related guides

Share this guide

Telegram WhatsApp

Already subscribed? Help for import & troubleshooting.

Ready for reliable international access?

View plans

This article is for technical education only. Comply with local laws when using network tools. Univista is not liable for how you use the service.