Hiddify TUN Mode Will Not Start or Has No Internet on Windows, macOS, and Linux
Troubleshoot Hiddify TUN/VPN mode startup failures, missing privileges, no network after connecting, and network problems after quitting.
TUN—shown as VPN or VPN Service in some versions—creates a virtual network interface and changes system routes. It therefore depends more heavily than a normal system proxy on administrator privileges, operating-system network components, and the state of other VPN software.
Symptoms
- TUN disconnects immediately and reports
operation not permitted, a service startup failure, or insufficient privileges. - System proxy mode works, but all requests time out after switching to TUN/VPN.
- The app says it is connected, but there is no latency result, websites do not open, or large responses never finish loading.
- The system still has no network access after Hiddify exits.
- Only one of Windows, macOS, or Linux fails while the same subscription works on a phone.
The official Hiddify guide explicitly says to start the application with administrator or root privileges before enabling TUN; see the official HiddifyApp usage guide. Issue #1982 in the official repository also shows an inbound-listener operation not permitted error on Linux.
Two-minute diagnosis
- Quit Hiddify completely, including its system-tray or menu-bar background process.
- Start it with administrator or root privileges using the normal method for the operating system, then enable only TUN for one test.
- If system proxy works and TUN fails, the subscription and node are probably not the first problem. Continue with privileges, the virtual adapter, and routing.
- Pause other VPNs, proxies, accelerators, virtual-machine networking, and traffic-filtering software, then test once more.
- Try another network and a known-good node. If every mode fails, return to the main troubleshooting guide to check the subscription and server.
Troubleshoot by layer
Client and privileges
Windows
- Exit the app from the system tray, then right-click Hiddify and choose “Run as administrator.” Closing only the main window may not stop the background process.
- Check whether another VPN, proxy, or security application with network filtering is running. Pause the conflicting program first; do not uninstall operating-system security components.
- If system proxy works but TUN does not, record the Windows version, Hiddify installation source, and error log.
macOS
- Quit the old process and check whether macOS shows a network extension, VPN configuration, or permission request.
- Approve system privileges only for a verified official package. Do not install profiles or certificates supplied by a third party.
- If permission was denied, reopen the app and follow the system prompt to review Privacy & Security settings.
Linux
- TUN and route operations require the relevant privileges. Follow the official documentation with a trusted package and its documented root launch method.
- If the log contains
operation not permitted,address family not supported, or an inbound-listener failure, record the distribution, kernel, package format, and complete error line. - Do not copy recursive deletion commands from Issue comments. Removing app data loses configuration and does not prove the root cause.
Subscription: use proxy mode as a control
- If the same node works through system proxy and only TUN fails, the remote node can at least establish a connection. Prioritize the local TUN path.
- If both modes fail, check the account, traffic quota, and node status, then read Connected but no internet.
- If refreshing the profile fails, resolve the subscription update problem first.
DNS/TLS and routing
- Restore the default TUN, routing, and DNS options before establishing a baseline.
- If the log shows only domain-resolution failures, change the network and compare system proxy mode before changing the MTU.
- If small requests work but images and large pages stall, record that behavior and the current MTU for a developer or provider to assess. Official Issue #1964 contains an MTU hypothesis and a later correction, showing that it is not one answer for every device.
- If the network does not recover after TUN exits, first confirm that the Hiddify process has stopped, then check system VPN, proxy, and network-interface states. Do not use an untrusted “one-click network reset” script.
Server
If neither TUN nor system proxy connects and the same subscription also fails on another device, ask the provider to check nodes, protocol parameters, certificates, traffic quotas, and concurrency limits. The Hiddify client cannot repair a closed remote port or incorrectly delivered configuration.
Verification
- After starting with the correct privileges, TUN connects three consecutive times without a service startup error.
- Two HTTPS domains and one commonly used app are accessible.
- Pages containing images or larger responses load, rather than only a small connectivity check.
- Direct network access returns immediately after disconnecting TUN.
- The result remains consistent after quitting and restarting Hiddify completely.
When to contact the provider or submit an Issue
If both system proxy and TUN fail, contact the subscription provider first. If only TUN fails consistently after using the correct privileges, pausing conflicting software, and restoring default settings, submit the problem to the official Issues.
Include the operating system and kernel/version, Hiddify version, package type, connection mode, whether administrator/root privileges were used, system-proxy comparison, shortest reproduction steps, and redacted logs. Do not include the subscription token, server credentials, or complete configuration.