V2Ray Setup Guide: From Subscription Import to Connection Verification

Complete four steps in order: import the subscription, choose a proxy mode, connect to a server, and verify traffic. This guide covers only the steps needed for first-time setup; protocol concepts and advanced routing parameters are covered in the glossary and complete installation guide.

v2rayN desktop v2rayNG for Android Subscription → Mode → Connect → Verify

Prepare the subscription URLand client

Before starting, prepare a valid subscription URL that the client can read. Providers usually generate it in the user panel, and it may contain VMess, VLESS, Trojan, or Shadowsocks configurations. Keep the complete scheme, domain, path, and parameters when copying it. Do not remove characters after the question mark or mistake a webpage URL for a subscription URL. Because a subscription can expose server configurations, do not post it on public pages, in group-chat screenshots, or in troubleshooting logs.

Use v2rayN on desktop and v2rayNG on Android. If the client is not installed, open the installer page, choose the right platform, and then return to this guide. You do not need to understand every protocol field before your first setup; once the subscription updates and servers appear in the list, you can continue. Look up VMess, VLESS, transport methods, TLS, REALITY, and Xray in the glossary as needed.

Import the subscriptionand update the server list

The goal of importing a subscription is not merely to save its URL in the client. The client must successfully read the remote content and turn its configurations into selectable server entries. When complete, you should see server names, protocol types, or a subscription group—not just a subscription URL. If the list is still empty, do not move on to proxy mode settings; there is no active server to connect to yet.

v2rayN desktop instructions

Open the v2rayN main window, find the subscription-group option in the top menu, and add a new subscription. Enter a recognizable name such as “Primary subscription,” then paste the complete subscription link into the URL field. Check that there are no spaces at either end, then save. Saving only records the source; you still need to update it from the subscription-group menu. Keep the network available while v2rayN requests and parses the content.

After a successful update, several configuration rows should appear in the server list. Open the subscription group to confirm that the entries belong to the source you just added. If the window is still empty, run the update again. For request or parsing errors, check whether the link was copied completely, the subscription has expired, and the current network can reach the source. Do not repeatedly change protocol, security, or transport settings before the subscription has been parsed; those parameters have not entered the client yet.

v2rayNG Android instructions

Open v2rayNG, go to Subscription settings from the top-right menu, and create a subscription entry. Add a recognizable note, long-press the URL field to paste the complete link, and save it. Return to the configuration list and use the menu to update subscriptions. Some versions return to the list after updating, while others show a brief result message; the key sign of success is that selectable entries appear in the configuration list.

If the provider gives you a single sharing link beginning with vmess://, vless://, trojan://, or ss:// instead of a subscription URL, use an option such as “Import from clipboard” to add that configuration. A single imported link does not provide automatic subscription updates, so you must import it again when the service parameters change. For long-term use, save the subscription URL provided by the service so it can be updated centrally.

Confirm the result

This step is complete when the client contains a subscription group with at least one selectable server configuration. Do not judge speed by the name or make bulk changes yet. Select one entry as the test server for the next step. To understand the relationship between subscriptions, nodes, and server configurations, see subscription and node terminology, then return to Step 2.

Choose a proxy modeto decide which traffic enters the client

After the subscription updates, decide how the client should handle device traffic. The common choices are rule-based routing, global proxy, and direct connection. The mode controls traffic routing; it cannot fix an unavailable server or change subscription content. For a first test, start with the client's default rules or “bypass mainland China” mode. Matching connections use the proxy, while the rest stay direct, making it easier to balance local services with proxied destinations.

How to choose among the three modes

Rule-based routing suits everyday use. The client uses domains, IPs, geolocation data, or preset rules to decide where traffic goes: requests matching proxy rules use the current server, while direct-rule matches connect directly. Global mode sends most traffic it can intercept through the current server. It is useful for briefly checking whether rules are the problem, but it does not guarantee that every application is intercepted. Direct mode bypasses the proxy and is mainly useful for pausing the proxy, comparing network behavior, or troubleshooting the local connection.

If you only need to verify the first connection, start with rule-based routing. If a site fails in rule mode but works globally, inspect the routing rules instead of repeatedly changing servers. Domain rules, IP rules, GeoSite, GeoIP, sniffing, and FakeDNS serve different purposes; this guide does not cover parameter combinations. For systematic changes, see the routing chapter in the complete guide.

v2rayN desktop settings

In the v2rayN main window or tray menu, find the routing mode and choose “bypass mainland China” or the default rules option provided by your version. Check that the current selection has changed. For now, only set the routing rules; do not enable the system proxy yet. The system proxy determines whether browsers and apps that follow system settings send requests to v2rayN. Enable it together with the selected server in the next step so each action is easier to evaluate.

If the window offers “Global” and “Direct,” use them for comparison when connection verification fails: if rule mode fails but global mode works, the server is usually available and the issue is more likely rule matching; if both fail, check the server, network, or core logs. Do not change the routing mode, core type, and subscription parameters at the same time, or the test will contain too many variables to isolate the cause.

v2rayNG Android settings

Open routing settings and choose one of the client's existing rule schemes. There is no need to create complex rules or enter domains individually for a first setup. If per-app proxying is enabled, confirm that the target app is included; otherwise the client may show as connected while the app continues using a direct connection. For the first test, disable per-app restrictions and narrow the scope after the basic connection works.

Return to the main screen and confirm that the imported configuration is still selected. The mode and server are now ready; the next step is simply to start the connection. Names vary slightly across versions, but the principle is the same: rule mode routes by matches, global mode expands proxy coverage, and direct mode does not use the current proxy server.

Choose a server and connectto route system traffic through the client

Before connecting, three conditions should be met: the subscription updated successfully, servers appear in the list, and the proxy mode is set. Now choose one configuration as the active server. A server name is only a provider-supplied label and does not prove that the configuration works. The real tests are whether the core starts, the handshake completes, and the target app can reach its destination through the current routing rules.

v2rayN desktop connection

Click the target entry in the server list, then use the context menu or press Enter to set it as the active server. The selected entry usually changes color, font, or status marker. Next, open the system proxy menu and choose “Set system proxy automatically” or the equivalent enable option in your version. This points the system proxy to v2rayN's local listening port, allowing browsers and apps that follow system proxy settings to send requests to the client.

Afterward, check the status at the bottom of the window or the tray icon to confirm that the core has started. If the client reports that a port is already in use, another program is using the same local port; exit the old proxy client and restart v2rayN. If the core stops immediately after starting, open the logs and inspect the first error rather than only the last line. Invalid configuration, an unreachable destination, and a local port conflict require different fixes; the first clear error is usually closest to the cause.

Some apps do not read system proxy settings and may remain on a direct connection even when v2rayN is connected. For the first test, use a browser that follows the system proxy to confirm the basic path. To intercept more programs, see TUN and platform-specific settings in the complete guide; do not add extra network layers during the initial connection.

v2rayNG Android connection

Select a server in the configuration list and confirm that it is marked as the current configuration, then tap the connection switch on the main screen. The first time Android creates a local VPN tunnel, it displays an authorization dialog. Approve it so the client can handle network requests from the selected apps. Return to the main screen; the switch and status area should show that the connection is active, and the system status bar will usually display a connection indicator.

If the connection quickly returns to a disconnected state, open the logs and inspect the core startup messages. Common causes include expired configuration parameters, incomplete subscription parsing, an unreachable server, or a battery-saving policy that stops the background process too soon. Keep v2rayNG in the foreground for one browser test first. Once the basic connection works, adjust the device settings to allow continued background operation. Background persistence is a device-management issue, not something to fix by repeatedly changing protocol fields.

Do not run bulk speed tests yet

The priority during first-time setup is confirming that one normal request can complete. Bulk speed tests contact multiple servers at once, and their results are easily affected by the current network, server load, and test destinations. Complete Step 4 with one server first; if it fails, compare it with another entry from the same subscription. If several entries fail at the same stage, the issue is more likely the subscription source, local network, system proxy, or client settings than one server name.

Verify that it worksand distinguish connected from proxied

A client status of “Connected” only means that the local core or network tunnel has started; it does not guarantee that the target app's requests use the current server. Verify the app's result, public network exit, and client logs together. When all three align, you can confirm that the complete path from the app to the local proxy and remote server is working.

Start a new browser request

Close the test page and reopen it, or use a new private window to visit a page that displays public network exit information. Do not merely refresh an existing page: browser caches, persistent connections, and DNS caches may preserve results from before the connection. Record the public exit before and after connecting. If it changes as expected and ordinary pages load reliably, browser traffic is entering the proxy.

If the exit does not change, first check that v2rayN's system proxy is actually enabled, then make sure the browser is not configured to use a different proxy. On Android, check the per-app proxy scope and confirm that the test browser is not excluded. If the exit changes but some sites do not load, return to Step 2 and compare rule mode with global mode to identify a routing-match issue.

Use logs to determine traffic flow

Keep the client log window visible and open a test page again. Normally, the logs will show a connection record corresponding to the new request time. If the browser clearly makes a request but the logs show no new entry, traffic may not be reaching the client; check the system proxy, per-app scope, or the app's own proxy settings first. If the logs show a request followed by a timeout, handshake failure, or unreachable destination, traffic has reached the client and the issue lies with the server connection or configuration parameters.

Logs may contain server addresses, domains, and subscription configuration details. If you need a troubleshooting screenshot, capture only the portion that identifies the error type and redact the subscription URL, user identifiers, and server authentication fields. Never publish the complete configuration. Look up protocol fields in the glossary; systematic log troubleshooting is covered in the troubleshooting chapter of the complete guide.

Cross-check with a second app

After the browser test succeeds, test another app that follows the system proxy or is included in the interception scope. If the browser works but the other app uses a direct connection, that app likely ignores the system proxy or is excluded from per-app routing; there is no need to reimport the subscription. If no app can connect, return to the connection status and logs instead of blaming a single app.

Once verification passes, first-time setup is complete. Daily use can usually be reduced to three actions: update the subscription, choose a server, and connect. If an update replaces the current server, select an active entry again. After changing networks, a brief interruption can often be fixed by disconnecting and reconnecting to rebuild the local tunnel rather than deleting every configuration.

Connection failedcheck each layer in order

Do not delete the subscription, switch cores, change routing, and reinstall the client all at once. Check each layer in order and record a clear result at every step.

  1. Confirm that the subscription updates

    Run a subscription update manually and check for an expired link, request failure, or parsing error. If the list is empty, fix the subscription before testing the connection.

  2. Try another server from the same subscription

    Change only the active server, leaving the proxy mode and other settings unchanged. If one entry fails while another works, the client's basic configuration is functional.

  3. Compare rule mode with global mode

    If rule mode fails but global mode works, inspect domain or IP routing matches. If both modes fail, continue by checking the system proxy, logs, and server connection.

  4. Check whether traffic reaches the client

    Make a browser request and watch the logs. If there is no new record, check the desktop system proxy or Android per-app scope. If there is an error, follow the first clear error to locate the cause.

  5. Handle platform-specific settings last

    After confirming the basic path, adjust TUN, background persistence, per-app proxying, and custom routing. Move complex cases to the complete guide instead of adding too many variables to the beginner flow.