Configuration and Troubleshooting

V2Ray FAQ

Covers client selection, subscription imports, routing modes, system proxy, TUN permissions, node timeouts, and DNS troubleshooting. Start by matching the symptom to a category, then check the settings one by one.

Issue categories

Browse by issue type

Expandable items use the browser’s native details component. They can still be opened and read one by one even if JavaScript does not load.

Core concepts

Start by separating the client, core, protocol, and proxy mode so you troubleshoot at the right configuration layer.

What are V2Ray, v2rayN, and Xray?

V2Ray generally refers to the ecosystem of protocols and proxy tools associated with Project V. v2rayN is a desktop GUI client for managing subscriptions, servers, routing, and the system proxy; Xray is one of the cores that a client can invoke. The GUI handles configuration, while the core handles connections and traffic processing. They are different software layers.

Which client should I use on Windows, macOS, Android, or Linux?

v2rayN is a good first choice for Windows, macOS, and Linux, with a consistent desktop interface and subscription-group workflow. On Android, v2rayNG supports QR-code imports, subscription updates, per-app proxying, and routing settings; choose v2flyNG when you need the V2Fly core.

Can VMess, VLESS, Trojan, and Shadowsocks be included in one subscription?

Yes. The client parses each server entry according to its protocol field, as long as the client and core support that protocol. When several protocols appear in one subscription, there is no need to split it manually. Before choosing a server, check that the transport, TLS, port, and server name fields are complete.

What is the difference between the system proxy and TUN mode?

The system proxy mainly handles applications that follow the operating system's proxy settings. It is simple to configure and works well for browsers and most desktop software. TUN mode uses a virtual network interface to handle more types of traffic, including traffic from applications that ignore system proxy settings. TUN requires additional permissions and may be affected by security software, virtual network adapters, or other networking tools.

How should I choose between rule-based routing, global proxy, and direct mode?

For everyday use, rule-based routing is usually the best choice: routing rules decide whether traffic goes through direct or proxy. Global proxy sends most traffic the active proxy can handle to the current proxy outbound, making it useful for temporarily ruling out routing problems. Direct mode bypasses proxy outbounds and is often used to test the local network. After switching modes, revisit the target site to verify the result.

Installation and setup

Covers subscription URLs, sharing links, package architectures, and operating-system permissions.

How do I import a subscription URL into v2rayN?

Copy the complete subscription URL first. In v2rayN, open subscription group management, add a group, enter the subscription URL, save it, and run Update current subscription. When the update finishes, choose a server in the corresponding group and set it as the active server. If the list does not change, first confirm that the group you are viewing is the same group you just updated.

What should I do if a subscription update fails or the parsed list is empty?

Copy the subscription URL again and check that neither end is truncated and that no spaces were added to the link. Then make sure the subscription group does not have overly strict remark filters enabled, and try toggling whether the subscription should be updated through the proxy. If content downloads successfully but parses to an empty list, check whether the subscription format is supported by the client.

Why can’t I see any servers after importing from the clipboard or a QR code?

Make sure you copied a complete sharing link or that the QR code contains a valid configuration, rather than an ordinary web address. After importing, check the current subscription group and server filter, and clear any remark, protocol, or group filters. If the client reports an unsupported format, use subscription import instead, or confirm that the link uses a supported format such as VMess, VLESS, Trojan, or Shadowsocks.

Should I choose arm64 or universal for an Android package?

Most mainstream Android phones released after 2015 can start with arm64. It is a smaller download and suits common 64-bit ARM processors. Choose universal if you cannot confirm the processor architecture, the device is older, or arm64 installation fails. A universal package supports more architectures, so it is usually larger.

What should I do when macOS says the developer cannot be verified?

First, confirm that the installer came from the client download entry on this site. If macOS blocks the first launch, open System Settings, go to Privacy & Security, and confirm that you want to open the app in the security notice. When enabling the system proxy or TUN, macOS may also request network extension, administrator, or VPN configuration permissions. Grant only the permissions required by the feature in use.

Usage tips

Practical guidance for choosing servers, organizing subscription groups, switching modes, and migrating configurations.

How should I use latency test results when choosing a server?

Prioritize real connection latency or actual access results rather than basic network probes alone. Lower latency generally means a shorter round-trip time, but it does not directly indicate bandwidth, stability, or performance during peak hours. First narrow the list to a few servers with normal latency, then use web loading, file transfers, and sustained usage to choose the best everyday option.

How can I update subscriptions automatically without losing my current selection?

Enable automatic updates in the subscription group settings, and create separate groups for different sources. When selecting servers, rely on stable remarks or group filters rather than list row numbers. If a subscription frequently renames servers, note the current server’s protocol, address, and port before updating, then confirm that the active server still exists afterward.

Should I keep multiple subscriptions in one group or manage them separately?

Create separate groups by subscription source or use case, such as home, work, and testing. Independent groups let you configure update methods, filter expressions, and update intervals separately, and make it easier to identify which subscription failed. Combining them is simpler only when there are few servers and they come from the same source.

How can I temporarily switch to global proxy without changing existing routing rules?

Switch to global proxy from the client’s routing mode or system tray menu; there is no need to delete existing rules. After testing, switch back to rule-based routing. Existing geosite, geoip, and custom domain rules will remain. If the behavior does not change, confirm that the active configuration has reloaded, close the target app’s existing connections, and try again.

How can I preserve subscription groups and routing settings when replacing a computer?

Use the client’s configuration backup or export function first, and record subscription groups, routing rules, DNS, and parameter settings. After migrating, install the same major client version, import the configuration, and check the core path, log directory, and system proxy options. Settings containing local paths may need to be selected again under the new system directories.

Troubleshooting

Narrow the problem down through five areas: connections, routing, the system proxy, virtual network adapters, and DNS.

What should I do if the client says it is connected but web pages will not open?

First, confirm that an active server is selected and check the logs for connection refusals, handshake failures, or DNS errors. Then switch to another known-good server and temporarily test with global proxy. If global mode works, focus on the routing rules. If it still does not work, check the system clock, server parameters, local firewall, and DNS settings.

What should I check if server tests keep timing out?

Check the server address, port, UUID or password, transport, TLS, SNI, and path fields in order. A timeout affecting one server is usually related to its configuration or remote status. If every server times out, check the local network, firewall, system clock, and whether the client core started correctly. The first error in the logs is usually more useful than repeated tests.

What should I do if some applications still connect directly after enabling the system proxy?

Some applications do not read the operating system’s proxy settings, or they cache an old proxy at startup. Fully exit and reopen the target application, then confirm that v2rayN wrote the correct system proxy address and port. If the application supports its own proxy settings, enter the client’s local listening address. If that still has no effect, consider using TUN mode to capture its traffic.

What should I do if TUN mode fails to start or repeatedly requests permission?

Confirm that administrator, VPN configuration, or network extension permissions have been granted, and check whether other TUN, VPN, or virtual network adapter tools are running at the same time. Close conflicting programs and restart the client, then check the logs for network adapter creation or route-writing errors. If permissions changed after a client update, remove the old virtual interface and enable TUN again.

What should I do if connections work but domains do not open while direct IP access works?

Check DNS first. Confirm that the client’s DNS configuration includes at least one working query server, and check whether routing rules are sending DNS requests to the wrong outbound. Temporarily disable custom DNS, FakeDNS, or complex routing and try again. Once access is restored, re-enable the settings one at a time to identify the conflicting configuration.

Continue

Follow the setup path for complete steps

For basic connection issues, start with the subscription import guide. For routing rules, DNS, TUN, and multi-subscription management, open the advanced configuration manual.

Download V2Ray client