This guide is for v2rayNG users who have imported a subscription but are unsure about the first permission prompt, lose connectivity after locking the screen, or want to proxy only selected apps. By the end, you will know how to grant VpnService permission, adjust battery restrictions, configure per-app proxying, and use logs and connection status to diagnose common problems.
Check the prerequisites before connecting
v2rayNG is a graphical Android client that commonly uses the Xray core to process VLESS, VMess and other configurations. After importing a subscription, the app passes node parameters to the core, which creates a local virtual network interface through Android's VpnService. Here, “VPN” refers to the system traffic-capture mechanism; it does not fill in a server address, user identifier, TLS domain or Reality parameters for you. Those details must still come from a valid subscription or a complete manual configuration.
Before you begin, check that the system time is set to sync automatically. TLS connections rely on an accurate clock; a large time offset can cause errors such as a certificate not yet being valid, an expired certificate or a failed handshake. Open system “Settings” → “System” → “Date & time” and enable automatic date and time and automatic time zone. Menu names vary by device, so you can also search for “Date & time” in system settings.
Local ports and MTU values may vary by version, configuration template or user changes. Treat these numbers as troubleshooting references, not settings to copy blindly. If you changed a parameter before, check the local SOCKS port in v2rayNG “Settings”. If the network connects but some pages keep loading, test an MTU of 1500, 1400 or 1280; change only one value at a time and reconnect after each test.
- Confirm that the subscription is still valid and run a subscription update once.
- Select a node from the node list so its name appears as the active configuration.
- Close other network tools that are currently using VpnService to prevent them from replacing one another's connections.
- For the first round of troubleshooting, keep the default routing and DNS settings. Do not change several groups of advanced parameters at once.
Grant VpnService permission for the first connection
When you tap the connect button on the v2rayNG main screen, Android displays a system-level connection request. This dialog is provided by Android; v2rayNG cannot create the virtual network interface or capture device traffic until you confirm it. The prompt usually appears only on the first connection, after app data is cleared, or after the system revokes permission.
Android normally allows only one active VpnService at a time. If another network tool is already connected, starting v2rayNG may disconnect it; starting another tool later may replace v2rayNG in turn. A key-shaped or VPN indicator in the status bar only confirms that the system interface exists—it does not prove that the remote node is working.
Select a node
Tap the target node in the v2rayNG configuration list. Use the top-right menu to run “Test all configurations for real connection” or run a latency test for the target node first. A latency result only shows whether the test request returned; you still need to verify an actual connection.
Start the connection
Return to the main screen and tap the circular connect button at the bottom. On the first use, wait for Android to show the VpnService connection request instead of tapping repeatedly.
Confirm permission
Confirm the connection in the system dialog. If the device uses a work profile, parental controls or enterprise management policies, the permission screen may be restricted by administrator rules.
Check the status
Make sure the main screen changes to Connected, then open a familiar website to test it. If the status quickly returns to Disconnected, open “Menu” → “Logs” immediately.
Trigger the prompt again
If the dialog does not appear, disconnect other VpnService instances first. Then open system “Settings” → “Apps” → “v2rayNG”, tap Force stop, reopen the app and connect again.
Exclude v2rayNG from battery optimization to reduce lock-screen disconnects
Many devices restrict background activity after the screen has been off for a while. Although v2rayNG can show a foreground-service notification, it may still be affected by battery optimization, background-start restrictions, sleeping-app lists or data-saver mode. A typical symptom is normal operation while the screen is on, followed by delayed messages after 5 to 20 minutes of screen-off time; reopening v2rayNG then restores the connection.
Prefer the system's per-app battery settings instead of disabling power saving for the entire device. Open system “Settings” → “Apps” → “v2rayNG” → “Battery” and choose “Unrestricted”, “Not optimized” or an equivalent option. If that entry is unavailable, search system settings for “Battery optimization”, switch to all apps and find v2rayNG.
App battery policy
- Menu path
- Settings → Apps → v2rayNG → Battery
- Recommended option
- Unrestricted or not optimized
- Test duration
- 15 minutes with the screen locked
- What to observe
- Whether the connection and messages continue
Names differ across systems; the goal is to allow the foreground service and necessary background network activity.
Background activity permission
- Menu path
- Settings → Apps → v2rayNG
- Background activity
- Allow
- Auto-start
- Enable if required by the system
- Recent apps
- Avoid one-tap cleanup
Some devices split background activity, auto-start and battery policy into three separate switches. Check each one individually.
Data Saver mode
- Menu path
- Settings → Network → Data usage
- Background data
- Allow
- Unrestricted data
- Enable as needed
- Test networks
- Mobile data and Wi-Fi
If disconnects occur only on mobile data, focus on background data and unrestricted-data permissions.
Foreground notification
- Menu path
- Settings → Notifications → v2rayNG
- Service notification
- Allow notifications
- Status check
- Remains visible while connected
- Warning sign
- The notification disappears and the service stops
The service notification shows runtime status. On some systems, disabling notification permission can also affect foreground-service stability.
After making changes, do not stop at a one-minute test. Connect to a node, turn off the screen for 15 minutes, then use both Wi-Fi and mobile data to receive messages and open websites. If the connection breaks only when switching from Wi-Fi to mobile data, wait 5 to 10 seconds to see whether it recovers automatically. If it does not, disconnect and reconnect, then check the logs for timeouts, DNS failures or unreachable-network errors.
Configure per-app proxying for your needs
Per-app proxying determines which app traffic enters v2rayNG's virtual network. It is useful when you want only a browser, messenger or specific work app to use the current node while banking, local-network management or network-location-sensitive apps stay direct. This feature controls the app scope; it is not the same layer as routing by domain, IP address or port.
The usual v2rayNG path is “Settings” → “VPN Settings” → “Per-app proxy”. Some versions show “Per-app proxy” directly in the side menu. Enable the feature first, then choose a proxy mode. If the wording changes after an update, search the settings page for “Apps” or “VPN”.
Open Settings
Open v2rayNG and go to “Settings” → “VPN Settings” → “Per-app proxy”. If the side menu already has the same entry, open it directly.
Enable the feature
Turn on “Per-app proxy”. Before enabling it, note the current node and routing mode so you can restore the original configuration if anything changes.
Choose a mode
Choose “Proxy only selected apps” or “Bypass selected apps” as needed. The first suits a small number of apps that need the proxy; the second suits setups where most apps use the proxy and only a few stay direct.
Select apps
Choose the target apps from the app list. System component names can be difficult to identify, so for a first setup select only user apps you clearly recognize.
Rebuild the connection
Save the settings, return to the main screen, disconnect and reconnect so the new app scope takes effect in the current VpnService session.
Verify apps individually
Open one selected app and one unselected app separately, then check whether websites, sign-in flows and local-network access behave as expected.
“Proxy only selected apps” gives you tighter scope control, but newly installed apps are not added automatically. “Bypass selected apps” requires less maintenance, but you must watch system components and shared network services. Some apps use a system web component, download manager or external browser to complete sign-in. If those helper components do not follow the same policy, the sign-in page may not open, downloads may not start, or the network path may change after a redirect.
| Use case | Recommended mode | What to check |
|---|---|---|
| Proxy only two or three specific apps | Proxy only selected apps | Newly installed apps must be added manually |
| Most apps should use the current node | Bypass selected apps | Add local-network and sensitive apps to the bypass list |
| An app opens an external browser | Keep both policies consistent | Sign-in callbacks and verification-code pages |
| Need to access a router admin page | Combine routing rules with a direct local-network route | Common private address ranges and local DNS |
Troubleshoot subscriptions, routing and DNS by layer
A node connecting does not mean every domain will resolve correctly. The v2rayNG path includes at least the subscription configuration, Xray core, DNS queries, routing rules and Android VpnService. Troubleshooting layer by layer is more effective than constantly switching nodes.
The subscription provides the server address, port, user identifier, transport method and security-layer parameters. Common VLESS + Reality fields include serverName, publicKey, shortId, fingerprint and flow; common VMess + WebSocket + TLS fields include the hostname, path, TLS settings and user identifier. These are usually filled in automatically after importing a subscription, but any missing key field can cause a handshake failure.
VLESS + Reality
- Transport
- TCP
- Flow
- xtls-rprx-vision
- Fingerprint
- chrome
- Key fields
- publicKey and shortId
Use the complete configuration supplied by the subscription. Do not guess security-layer fields from a node name.
VMess + WS + TLS
- Transport
- WebSocket
- Path
- Provided by the subscription
- TLS
- Enable according to the configuration
- Key fields
- Host and SNI
A path, Host or SNI mismatch commonly causes connection timeouts or TLS handshake failures.
Routing rules determine whether traffic goes through the proxy, connects directly or is blocked after matching. Per-app proxying first limits the app scope; routing rules then process the domains and IP traffic generated by those apps. When you need to access a printer, router or home storage device, keep local-network addresses on a direct route. Common private ranges include 192.168.0.0/16, 10.0.0.0/8 and 172.16.0.0/12.
DNS failures often appear as websites that do not open while direct requests to some IP addresses still get a response. For troubleshooting, restore v2rayNG's default DNS settings and reconnect, then check the logs for resolution timeouts. If the problem occurs only on a particular Wi-Fi network, compare it with mobile data. If both networks fail, inspect the node configuration, subscription update and DNS rules more closely.
- After updating the subscription, select the target node again so you do not continue using an outdated configuration.
- After changing DNS, routing or per-app settings, disconnect and reconnect.
- A failed latency test does not necessarily mean the server is completely unavailable; assess it together with a real-connection test and the logs.
- Temporarily increase the log level during troubleshooting, then restore the normal level once the cause is confirmed to limit ongoing logging.
Quick fixes for common problems
During troubleshooting, record which network was used, which app was affected, how long the screen was locked, whether the network changed and what the logs reported. This is far more useful than simply saying “it won't connect”. The following cases cover the permission, background-restriction and app-scope problems most often seen during initial setup.
No permission dialog after tapping Connect?
Disconnect any other active VpnService first, then open system “Settings” → “Apps” → “v2rayNG” and tap Force stop. Reopen v2rayNG and tap the connect button once. If the device is controlled by a work profile or management policy, confirm that the administrator allows VPN connections.
Disconnected after ten minutes of screen-off time?
Open system “Settings” → “Apps” → “v2rayNG” → “Battery”, select “Unrestricted” or “Not optimized”, and allow background data and service notifications. Lock the screen for 15 minutes and test again; do not clear v2rayNG from recent apps.
Connected, but websites will not open?
Switch to a node already confirmed to work, update the subscription and restore the default DNS settings. Then check “Menu” → “Logs” for resolution timeouts, connection timeouts or TLS handshake messages. If only one app is affected, check whether per-app proxying excludes it.
Still connecting directly after selecting an app?
Confirm that the mode is “Proxy only selected apps”, save the settings, disconnect and reconnect. If the app uses an external browser or system download component, include the related component in the same policy and test the main app and redirected page separately.
Cannot recover after switching Wi-Fi?
Wait 5 to 10 seconds for the system to complete the network transition. If there is still no connection, disconnect and reconnect manually. If the issue repeats, test Wi-Fi and mobile data separately, then check battery restrictions, background data, Private DNS and MTU—changing only one item at a time.
After setup, keep a simple, reproducible baseline: a valid subscription, one stable node, default DNS, default routing and per-app proxying disabled. Once the baseline connection works, add battery policies, app scope and custom routing step by step. If a later change causes a conflict, you can quickly return to a known working state.