V2Ray FAQs and troubleshooting
Locate the configuration stage based on the symptoms. First verify the client, subscription, and node status, then check system proxy, routing mode, DNS, and TUN takeover. Avoid changing multiple variables at once.
- Subscriptions and nodesVerify the configuration source and active server
- Local traffic takeoverCheck the system proxy, VPN, or TUN
- Routing and DNSUse global mode for a comparison test
- Logs and conflictsLocate port, permission, and network errors
Keep one test variable at a time
Do not change the node, DNS, routing mode, and TUN at the same time. Start with one complete node configuration, close other proxy tools, and use global mode to verify basic connectivity. Then restore routing and per-app settings one at a time.
Error messages and client logs are more useful for diagnosis than speed-test numbers. Record when the issue occurred, the current network, the active node, and recently changed options to distinguish subscription, node-parameter, and local takeover issues faster.
Getting Started
Separate the client, core, and protocol first; choosing the right package and configuration parameters will then be much easier.
What is the relationship between V2Ray, V2Fly, and Xray?
V2Ray generally refers to the protocol and tooling ecosystem created by Project V. V2Fly continues the community-maintained path of v2ray-core, while Xray extends compatibility with widely used protocols through features such as VLESS and REALITY. v2rayN is a desktop graphical client that can work with different cores; v2rayNG primarily uses the Xray core, while v2flyNG uses the V2Fly core.
How should you choose between v2rayN, v2rayNG, and v2flyNG?
Choose v2rayN first on Windows, macOS, and Linux for its centralized subscription, system proxy, routing, and logging controls. Android users generally choose v2rayNG for Xray-based configurations and related protocols; choose v2flyNG when V2Fly core compatibility is required. Their interfaces differ, but the basic subscription import, node selection, and routing workflow is similar.
What are the main differences between VMess and VLESS?
VMess includes user authentication and time validation, so it is common in older configurations. VLESS has a lighter design and is typically combined with TLS, REALITY, or other transport-security settings. The client must exactly match the server parameters, including the address, port, user ID, transport, TLS, SNI, and path. Changing only the protocol name will not establish a connection.
What is the difference between global, bypass-LAN, and rule-based routing modes?
Global mode sends connections within the client’s scope through the current proxy node and is useful for quickly testing node availability. Bypass-LAN mode preserves local access to printers, routers, and shared devices. Rule-based routing matches domains, IPs, ports, or apps to different outbounds, offering more flexibility for daily use; incorrect rule order or default outbound settings can make some websites unreachable.
Installation and Setup
Handle first-time setup issues involving subscription imports, package architectures, QR codes, and TUN permissions.
What should I check first when a subscription link fails to import?
First, confirm that the full subscription URL was copied, including its beginning, query parameters, and final characters. Save it with the client’s Add Subscription feature, then run an update manually. For format errors, make sure the URL returns client-compatible subscription data rather than a login page, web instructions, or an expired notice. For network errors, check the current connection, system time, and whether the subscription URL is still valid.
How can I import a subscription by QR code or manual configuration when the subscription is unavailable?
On Android, use Scan QR Code or Import from Clipboard on the main screen, making sure the QR code is complete and clear. For manual setup, enter the protocol, server address, port, user ID, transport, TLS, SNI, Host, and path in order. Desktop clients can use bulk import from the clipboard. After importing, verify the key parameters before setting the configuration as the active server.
Should I choose arm64 or universal for the Android package?
Most mainstream Android phones released after 2015 use 64-bit ARM processors, so arm64 is usually the best choice and has a smaller file size. If the architecture is unknown, the device is older, or arm64 is reported as incompatible, use the universal package. Both packages provide the same core features; they differ only in the processor architectures included, and you do not need to install both.
Why does TUN mode report insufficient permissions or fail to start?
TUN mode creates a virtual network interface, so it requires the system-requested VPN, network-extension, or administrator permissions. Exit other proxies, accelerators, and VPN tools using a virtual adapter, then restart the client and approve the permission prompt. On desktop systems, also check whether security software is blocking driver or network-interface creation. After granting permission, reconnect instead of only toggling the interface switch.
Advanced Tips
Adjust everyday settings for subscription updates, system proxy, per-app takeover, and remote DNS.
What should I do if a v2rayN or v2rayNG subscription update fails?
Update the target subscription separately and check the error message. Connection timeouts usually involve the current network, DNS, or subscription-service reachability. An unexpected status code may indicate an expired URL, changed permissions, or a redirect. If the update succeeds but no nodes appear, check the subscription-group filters. You can also temporarily disable old nodes and update again so cached data is not mistaken for the latest result.
The system proxy is enabled, but the browser still connects directly. What should I do?
Confirm that the client is running, then check that the local address and port configured in the system proxy match the client’s listening port. A separate browser proxy extension may override system settings, so disable it before testing. Some programs do not read the system proxy; use TUN mode or configure the proxy inside the program instead. After changing settings, close and reopen the target program so it reloads the system network configuration.
How do I configure per-app proxying on Android without missing apps?
Enable VPN mode first, then open the per-app proxy list and choose Include or Exclude mode. Include mode handles only selected apps and suits narrowly targeted use cases; Exclude mode handles every app that is not excluded and covers more traffic. Disconnect and reconnect after changing the app list. If an app still is not affected, check whether it connects through a system component, browser, or separate process.
Should remote DNS use a standard address or a DoH address?
Standard DNS usually uses an IP address, while DoH requires a complete HTTPS query URL, such as https://1.1.1.1/dns-query. The right choice depends on client and configuration support. If domains fail but IP addresses work, switch to a known-working remote DNS and check that routing rules send DNS requests through the correct outbound. Do not layer multiple system-level DNS tools at the same time.
Troubleshooting
Diagnose node timeouts, post-connection internet loss, Android background interruptions, and conflicts between multiple tools step by step.
What is the right order for troubleshooting node speed-test timeouts?
First synchronize the system date, time, and time zone, then confirm that the current network can access the internet normally. Next verify the server address, port, user ID, transport, TLS, SNI, Host, and path. If one node times out while others work, the issue is usually that node’s configuration or service status. If all nodes time out, focus on the local firewall, DNS, proxy-port conflicts, and network environment.
The client says it is connected, but there is no internet access. What should I do?
Run a comparison test in global mode first. If global mode works but rule mode does not, the issue is likely in routing rules, the default outbound, or DNS routing. If global mode also fails, check the active node, system proxy or VPN takeover status, local port, remote DNS, and logs in that order. If the browser works but other programs do not, confirm whether the target program reads the system proxy.
What should I do if the connection drops automatically after the Android screen locks?
Allow the client to run in the background in the system app settings, and set its battery policy to Unrestricted or allow continuous activity. Some systems also require auto-start, background pop-ups, or locking the app in recent tasks. Re-establish the VPN connection after changing these settings, then lock the screen and observe. If disconnections occur only when switching between Wi-Fi and mobile data, check whether automatic reconnect on network changes is enabled.
How can I recover from conflicts caused by multiple proxy tools running at once?
Exit other tools that modify the system proxy, DNS, routing table, or virtual network adapter, and leave only one client running. Then disable the current client’s system proxy and TUN, disconnect, and enable them again as needed. If the system proxy remains, restore it to automatic or disabled in the operating system’s network settings. When a port is occupied, check the client log, change the local listening port, and reconnect.
Continue to configuration steps
For a first installation, follow Getting Started to import a subscription, choose a node, and verify the connection. To adjust routing, DNS, TUN, or subscription groups, open Advanced Tips for the complete guide.