The Client Starts Normally
After opening, you can see a configuration list, subscription menu, or connection entry, with no recurring startup errors.
SETUP / 10 MINUTES
Complete four actions in order: import a subscription, choose a proxy mode, start the connection, and verify the result. This guide is for first-time setup and explains what to click, what to expect, and when to continue.
PREPARE
Confirm the prerequisites before opening the client. Problems during preparation usually prevent the connection steps from succeeding.
This guide assumes the client is already installed and opens normally. Use v2rayN on desktop devices and v2rayNG on Android devices. If it is not installed yet, go to the download center and choose a package that matches your operating system and processor architecture. After installation, launch the client, but do not change the port, transport parameters, DNS, or routing rules yet; the default settings make it easier to determine whether the subscription and nodes themselves are usable.
You also need a valid subscription URL. It is usually a complete text string beginning with https://, provided by your service provider. It is not an ordinary web address and is different from an individual share link beginning with vmess:// or vless://. A subscription returns a set of configurations at once, while a single-node share link represents one configuration. See the glossary for the distinction; this page covers only the subscription import process.
When copying a subscription URL, copy every character from the beginning to the end. Do not include spaces, line breaks, or explanatory text from either side of the message. Treat the URL as a configuration credential and avoid pasting it into public pages, search boxes, or unrelated software. If it has expired, obtain a current URL from the subscription provider first; changing client parameters cannot restore an expired subscription.
Finally, check that the system date, time, and time zone are correct, and enable automatic time synchronization. Some connection processes depend on accurate time, and a significant clock drift can cause the handshake to fail. Confirm that the device has a basic network connection before continuing with the four steps below. Here, “basic network connection” means that the device can still access everyday websites or update the subscription before the client proxy is started.
After opening, you can see a configuration list, subscription menu, or connection entry, with no recurring startup errors.
Copy the complete URL and confirm there are no spaces at either end and no explanatory text selected with it.
Enable automatic time synchronization and confirm that the device has a usable network connection before connecting the client.
Create a subscription group, fetch its configurations, and confirm that the node list has been added to the client.
After opening v2rayN, find “Subscription Groups” or a similarly named subscription management entry in the menu at the top of the window, then open the subscription group settings. Choose to add a new group and enter an easy-to-recognize note, such as “Common Subscription.” Paste the complete subscription URL you copied into the address field. Leave the other options at their defaults for now, then save and close the management window.
Saving the group only tells the client to remember the subscription URL; its nodes have not yet been fetched locally. Return to the main interface, open the subscription menu again, and choose “Update All Subscriptions” or update the group you just created. Do not click the same button repeatedly during the update. When it finishes, the server list in the main window should contain several configuration entries. It typically shows fields such as an alias, address, port, and transport type; the number of columns varies by version and window width.
Open v2rayNG, tap the top-right menu, and go to “Subscription Group Settings” or the subscription management page. Tap the add button, enter a note, paste the subscription URL, and save. Return to the configuration list, then use the top-right menu to “Update Subscription.” After a successful update, the main list will contain configurations from that subscription. If the list is still empty, do not proceed to connection, because an empty list means there is no active configuration to choose.
After importing, the first check is not latency testing. Confirm these three facts: the group exists, its update time changed, and entries appear in the list. Latency results depend on whether a node responds to the test request, current network conditions, and the client's testing method, so they cannot alone determine whether a configuration works. For a first setup, it is enough to see a configuration with a complete name in the list.
Once configuration entries appear in the list, the subscription import stage is complete. Do not edit the address, port, user ID, or transport parameters inside individual nodes; these fields should be maintained by the subscription. Next, decide how broadly the client should handle traffic—that is, choose a proxy mode.
The subscription group is saved, the update has completed, and the main configuration list contains at least one selectable configuration.
Start with rule mode for the initial verification, then adjust the traffic scope to fit your needs.
The proxy mode determines which connections the client handles. For an initial setup, start with rule mode. It uses the routing rules currently loaded by the client to decide where traffic goes, making it suitable for everyday use while preserving local networking and commonly direct services. Global mode sends a broader range of traffic through the current node and can help with comparison testing, but it is not recommended as a long-term setting when you are unsure of its scope. Direct mode is generally used to temporarily stop the proxy path and is not the target mode for this connection check.
In the v2rayN status area at the bottom of the main window, the system tray menu, or the “System Proxy” menu, find the system proxy options. Depending on the version, they may appear as “Auto Configure System Proxy,” “Clear System Proxy,” or similar names. For the initial setup, choose automatic system proxy configuration, then set the routing mode to rule mode. The status area will usually show the current system proxy state and routing mode; the system tray icon may change as well.
The system proxy mainly affects programs that follow the operating system's proxy settings, such as most browsers and some desktop applications. Some programs use their own networking implementation and may not read the system proxy. If one specialized program does not change, do not immediately rewrite the routing rules; first complete the fourth-step verification in a regular browser. For the scope differences between TUN and the system proxy, see the relevant section in the Complete Cross-Platform Setup Guide.
v2rayNG typically takes over traffic through the system VPN interface, so there is no desktop-style “System Proxy” menu to find. Open the navigation drawer or settings page and confirm that routing remains at its default or is set to rule mode. During first-time use, do not enable app filtering, complex DNS overrides, or custom routes at the same time; these features add troubleshooting variables. Return to the main configuration list. You should see the circular connection button at the bottom, but do not tap it yet—the active node must be selected in the next step.
Choose a mode by first obtaining a repeatable baseline result, then fine-tuning traffic routing. If you import many custom rules on the first attempt, a failed connection becomes difficult to attribute to the node, subscription, DNS, or rule matching. Rule mode with the default configuration reduces variables. Once the basic connection works, adjust settings one at a time as needed.
The desktop client has automatic system proxy configuration and rule mode enabled, or the Android client has retained the basic routing settings and is ready to use the system VPN connection.
Set one configuration as the active node, start the core, and watch the client's status change.
A subscription list may contain multiple configurations, but the client needs one clearly selected active node at a time. For the first connection, do not run batch tests or switch repeatedly; choose one clearly named configuration and complete the full process. Node names are usually defined by the subscription provider. The name itself does not indicate connection quality and cannot replace actual verification.
In the v2rayN server list, click the target row, then press Enter, choose “Set as Active Server” from the context menu, or use the equivalent command provided by the interface. The active server is usually marked by a color, icon, or status bar text. Confirm that the current server name in the bottom status bar matches the selected row before starting the system proxy. Some versions keep the core running automatically after a node is selected, while others control it through the tray menu. Use the log area as the guide: startup records should appear and the local proxy port should begin listening.
If the system displays a network access permission prompt, allow the client to make the required connections for the current network environment. Return to v2rayN and watch the log area. A normal startup usually shows configuration loading, core startup, and the local inbound beginning to listen. Log port numbers are local communication parameters, not the subscription node's port, so do not change them manually to match node information.
In the v2rayNG configuration list, tap the target configuration to make it the selected item. The selected state is usually shown by a marker beside the entry or its name in the main status area. Then tap the circular connection button at the bottom. The first time you start it, the system displays a VPN connection authorization dialog. Confirm it so the client can establish the local VPN interface. Follow the system prompt and do not switch to another app while the dialog is open.
After the connection button changes state, the notification area will usually show that the service is running, and the main interface will indicate that the connection has started. If it immediately returns to a disconnected state, open the log and inspect the latest error. Common causes include an unavailable node, incorrect system time, failed address resolution, or configuration fields that could not be loaded. Preserve the original error text and troubleshoot one variable at a time instead of randomly changing every setting.
A successful startup only means that the client core and local traffic interception entry are running; it does not guarantee that the target can be reached. After seeing “Connected,” continue to the next verification step. Use the client status, browser result, and log records together to distinguish an interface status from an actual traffic result.
An active node is clearly selected, the client shows that it is running or connected, and it does not stop immediately after startup.
Use a new browser session, client logs, and a comparison test to confirm the traffic path.
After starting the connection, open a new browser tab and visit a stable website with simple content. A new tab is preferable to refreshing a page that was already open before the connection, because the browser may reuse an old connection or cached result. Once the page loads normally, open a second website on a different domain for comparison, so an outage at one site is not mistaken for a client problem.
Next, return to the client and check the logs. During verification, the log should add a connection record with a time close to your browsing activity. On desktop, check the log area or log page in the main window; on Android, open Logs from the menu. You do not need to understand every internal field. First confirm that timestamps are updating and that the same error is not repeating continuously. If the browser works and new connection records appear, the basic setup can be considered complete.
To confirm that the browser is actually using the current proxy settings, run a brief comparison: record the result while the connection is enabled, then stop the connection or clear the system proxy on desktop, close the test tab, and reopen the same page. Re-enable the client after the comparison. The goal is not to obtain a particular result from a fixed page, but to confirm that changing the switch produces the expected change in the network path.
On desktop, if the client shows that it is running and the logs contain records but a specific program is unchanged, first check whether that program reads the system proxy. Verify the system proxy in a browser before deciding whether TUN is needed. On Android, if the connection button shows that it has started but no apps can access the network, check whether another VPN-type connection is running at the same time, because the system generally allows only one active interface of that type.
If the browser cannot complete the test, return to step one and update the subscription, confirming that the list still exists. Then check that the active node in step three is clearly selected. Next, restore rule mode and the default DNS from step two. Finally, reconnect using another configuration from the same subscription. Change only one item at a time and retest after each change so you can identify which change produced the result.
If the client repeatedly exits after startup, check the end of the log for a port conflict, configuration loading failure, or permission issue. For a port conflict, close other similar clients before restarting the current one. For a configuration loading failure, update the subscription again rather than manually assembling missing fields. For a permission issue, use system settings to allow the client's required network access. A more complete startup troubleshooting path is available in Frequently Asked Questions.
If some domains work while others do not, the basic connection is usually established and the problem is more likely in routing rules or DNS resolution. Reinstalling the client is unnecessary. Record the affected domains and current mode, then consult the routing and DNS sections of the Complete Setup Guide. Look up concepts such as protocols, inbounds, outbounds, and traffic routing in the glossary.
COMPLETE
Save a configuration that can be reproduced reliably before adding advanced settings one at a time.
After completing the four steps, keep the current subscription group, active node, and rule mode. Do not immediately change the port, DNS, routing, or app filtering in bulk. This baseline can serve as a fallback if problems occur later. A subscription update may replace or add and remove configuration entries, so a changed node name does not necessarily indicate a client failure; simply confirm the active node again after updating.
For everyday use, update the subscription according to the provider's schedule. After the update finishes, first check that the list looks normal, then select an active node. Frequent updates are not a cure for every connection problem. If the current node is failing, try another configuration from the same subscription; if the subscription itself cannot be updated, then check the URL status.
For startup configuration, TUN, app-based routing, custom DNS, or platform permissions, go to the Complete Cross-Platform Setup Guide. It explains installation and advanced settings by operating system. This page keeps to the basic workflow: every extended configuration should build on three results— the subscription updates, the node starts, and the browser can verify access.
Review installation details, platform permissions, and advanced settings for Windows, macOS, Android, and Linux.
TROUBLESHOOTIdentify the cause step by step by checking subscription updates, client startup, node connections, routing, and DNS.