RE:NODE

Networking11 min read

VLESS client setup: v2rayNG, Hiddify, Streisand, Shadowrocket

Import a vless:// link into v2rayNG, Hiddify, Streisand or Shadowrocket, connect, check it works, and fix the errors that stop a Reality profile connecting.

0 readers

Setting up a VLESS client takes about two minutes on any platform, because every mainstream client accepts the same thing: a single vless:// share link. You copy the link your server gives you, open the client, add a profile from the clipboard (or scan it as a QR code), select it and connect. On Android that means v2rayNG or Hiddify; on iPhone and iPad, Streisand, Shadowrocket or Hiddify; on a Mac, Hiddify; on Windows, Hiddify, v2rayN or, on RE:NODE, the Renode VPN app. Then you check three things - the public address, DNS and a real page load - before trusting it.

The steps are short. Most of this guide is about the parts that are not: what the link contains, what each field does when it is wrong, the difference between proxy mode and VPN mode, and the handful of reasons a Reality profile refuses to connect.

A share link is the whole client configuration squeezed into one URL. Knowing the fields turns "it does not connect" into something you can diagnose.

code
vless://3f2a9c1e-7b4d-4e21-9a6f-0c5d8e2b1a47@203.0.113.10:443?encryption=none&flow=xtls-rprx-vision&security=reality&sni=www.example.com&fp=chrome&pbk=Q9x...&sid=6ba85179&type=tcp#home
FieldExampleWhat it does
user ID3f2a9c1e-...A UUID that identifies you to the server. This is the secret
host and port203.0.113.10:443Where the server is
encryptionnoneVLESS does no encryption itself; Reality provides it
flowxtls-rprx-visionThe Vision flow, which avoids an obvious TLS-inside-TLS pattern
securityrealityUse the Reality transport security
snia well-known siteThe site whose TLS handshake is borrowed
fpchromeWhich browser's TLS fingerprint to imitate
pbkbase64 stringThe server's Reality public key
sidshort hexA short ID the server accepts
typetcpThe transport, plain TCP here
after #homeJust a display name for the profile

If any of pbk, sid, sni or the UUID is wrong by one character, the server treats you as a stranger and quietly passes you through to the real website. From the client's side that looks like a connection that opens and then carries nothing. VLESS and Reality explained covers why the server behaves that way.

On RE:NODE the server prints its link once it is set up; copy the whole thing. Links are long, and the most common failure of all is a link truncated by a messaging app or a text editor that wrapped it. Send it to yourself through something that does not mangle long URLs, or show it as a QR code on one screen and scan it from the phone.

Two other things to check before blaming the client:

  1. Captive portals. On hotel and airport wifi, open a browser and accept the terms page first. Until you do, the network sends every connection to its own login page and no VPN can connect.
  2. One VPN at a time. Android and iOS allow only one active VPN. If another VPN app, a firewall app that works as a local VPN, or an ad blocker of that kind is on, the new one either replaces it or fails.

A legal note belongs here too: VPN use is restricted or regulated in some countries. Know what applies where you are before installing any of this.

Android: v2rayNG#

v2rayNG is the long-standing Android client, open source and built on the Xray core. It is on Google Play and as an APK in the project's GitHub releases; if you install from GitHub, take the build that matches your phone's CPU (almost every current phone is arm64-v8a).

  1. Copy the vless:// link.
  2. Open v2rayNG and tap the + at the top.
  3. Choose to import from the clipboard (or from a QR code to scan it with the camera).
  4. A new profile appears in the list. Tap it so it is the selected one.
  5. Tap the round connect button at the bottom right. The first time, Android asks you to allow a VPN connection request; accept it.
  6. A key icon in the status bar shows the VPN is up.

The status line at the bottom of the screen can run a connection test when tapped; it makes a real request through the tunnel and reports the time it took. That number is far more useful than any "ping" figure, which in proxy clients often measures only how fast a TCP connection to the server opens.

The settings worth knowing about in v2rayNG are the per-app proxy (choose which apps go through the tunnel, or which ones are excluded) and the routing settings, where local addresses can be sent direct. Both are covered in split tunnelling explained. Leave the rest alone until you have a reason.

Hiddify on Android, iOS, Windows, macOS and Linux#

Hiddify is the client to reach for when you want the same app on every device. It is open source, built on the sing-box core, and published for Android, iOS, Windows, macOS and Linux.

  1. Copy the link.
  2. Open Hiddify and tap + to add a profile.
  3. Choose to add from the clipboard. Depending on platform and version you also see options to add from a link or by scanning a QR code.
  4. Select the profile and press the large connect button on the home screen.

On desktop, pay attention to the mode. Hiddify can run as a system proxy or as a VPN (TUN) service. A system proxy only covers applications that respect the operating system's proxy setting - browsers do, many games, command-line tools and some desktop apps do not. If you want everything to go through the server, use the VPN mode; on Windows it needs to run with administrator rights to create the virtual adapter.

Hiddify also has routing options, including rules that send traffic for a chosen country directly instead of through the tunnel. Those are useful when local banking or government sites refuse foreign addresses, and they are a source of confusion when you forget you set one.

iPhone and iPad: Streisand and Shadowrocket#

Streisand is free on the App Store and supports VLESS with Reality alongside other protocols.

  1. Copy the link.
  2. Open Streisand and tap the + in the top right corner.
  3. Choose import from clipboard, or scan a QR code.
  4. Tap the new profile to select it, then switch the connection on.
  5. iOS asks whether to allow the app to add VPN configurations. Allow it, and confirm with Face ID, Touch ID or your passcode.

Shadowrocket is a paid app and is not sold in every country's App Store. It is popular for its rule-based routing. Add a server with the + button, either by pasting the link or by filling in the fields by hand: type VLESS, address, port, UUID, TLS on, security set to Reality, then the SNI, public key and short ID, and the Vision flow. The link is less error-prone than typing; use it when you can.

On both, iOS shows a VPN badge in the status bar while connected, and the connection appears under Settings, General, VPN and Device Management, where you can also delete stale profiles.

Windows: the Renode VPN app and alternatives#

On RE:NODE, Windows has its own client: the Renode VPN app takes the link your server prints and connects. Paste the link, connect, and you are done; there is nothing else to configure for the default full-tunnel setup.

If you prefer a general-purpose client, Hiddify for Windows and v2rayN both import the same link. v2rayN is the long-standing Windows client from the same family as v2rayNG; by default it works as a system proxy, so check its TUN or VPN mode if you need applications that ignore proxy settings to use the tunnel. Running two VPN clients at once on Windows is possible and is a reliable way to get confusing routes; pick one.

Checking that it really works#

A green button means the client started. It does not mean traffic goes where you think. Spend two minutes on this the first time on each device.

CheckHowWhat you want to see
Public addressOpen any "what is my IP" pageYour server's address, located in Germany for a RE:NODE server
DNSRun the extended test on a DNS leak test siteNo resolvers belonging to your local ISP or the wifi network
IPv6Open an IPv6 test pageEither no IPv6, or IPv6 that is not your own network's
Real browsingLoad a few sites, play a videoPages load, nothing hangs on "connecting"
SpeedRun a speed test with and without the tunnelSome loss is normal; a collapse is not

The DNS and IPv6 checks catch the leaks that matter most. If your ISP's resolvers show up, or your home IPv6 address appears while the IPv4 one is the server's, part of your traffic is bypassing the tunnel. VPN DNS leaks and how to test explains each case and the fix.

bash
# On a laptop, the same check from a terminal$ curl -4 https://ifconfig.me$ curl -6 https://ifconfig.me

The first should print the server's address. The second should fail or print an address that is not your home network's.

Updating clients and managing profiles#

VLESS clients are community projects that move quickly. Features such as Reality and the Vision flow arrived in specific core versions, and fixes for detection and stability keep coming, so an app left un-updated for a year is more likely to fail than one kept current. Install from the store where you can, so updates arrive by themselves; if you installed v2rayNG from GitHub, check its releases page now and then, because the APK will not update itself.

Profiles accumulate. Each time you import a link you get a new entry, and after a few months a phone can carry several copies with different names, only one of them current. Before importing a new link, delete the old profile, or at least rename the new one so you know which is which. Selecting a stale profile that points at an old key is a common cause of "it worked yesterday".

Some providers hand out a subscription link rather than a single profile: a URL the client fetches to get a list of servers, refreshed periodically. A private server with one link does not need that; the single vless:// link is the whole configuration.

Keep a copy of the link somewhere safe and offline - a password manager is ideal - so you can re-import it after replacing a phone or reinstalling a laptop without going looking for it. On a Mac, Hiddify is the straightforward choice; any client you choose takes the same link.

When a Reality profile will not connect#

Work through these in order; they are sorted by how often they are the answer.

The link is incomplete. Compare the end of the pasted link with the original. A missing pbk or sid gives a profile that "connects" and loads nothing. Re-import from a clean copy.

The client is too old. Reality and the Vision flow need a reasonably current core. An old v2rayNG or v2rayN that predates Reality either refuses the link or imports it without the Reality fields. Update the app.

The profile imported, but in proxy mode. Browsers work and the game, mail app or terminal does not. Switch to VPN or TUN mode, or check the per-app list.

Another VPN is active. Turn off the other VPN, ad blocker or firewall app, including always-on settings that will restart it. VPN kill switch and always-on explains how Android's always-on setting can hold a different app in place.

The network blocks the server's address outright. Some networks block by destination rather than by protocol. If the same link works on mobile data and fails on one particular wifi, that network is the problem, not the configuration.

Everything else works but it is slow. That is a different problem with different causes - distance, the path in between, CPU on a small plan. See why is my VPN slow.

FAQ#

Yes. The same link imports into every client, and on RE:NODE that is how phones and Macs are meant to connect. What limits you is how many devices use the server at the same time, which is what the plans are sized by.

Why does the app show a ping of a few milliseconds but pages are slow?

Many clients measure how quickly a TCP connection to the server opens, which says little about a real request through the tunnel. Use the client's real connection test, or time a page load, for a number that means something.

Do I need to install a certificate on my phone?

No. Reality does not use a certificate you install or trust. The client verifies the server with the public key in the link, so there is nothing to add to your device's certificate store.

Is Shadowrocket worth paying for over Streisand?

Only if you want its rule-based routing and configuration options. For a single server and full-tunnel use, a free client does the same job. Both import the same link.

They can connect to your server and use its capacity, and their traffic leaves from your address. Treat the link like a password and keep it off chats and screenshots. If you think it has leaked, open a ticket from the panel.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000