Client Settings Reference / Quick Guide

V2Ray Glossary

Look up concepts by where they appear in your setup, from protocol types to system proxy settings. Each entry explains what it does, where it is commonly configured, and what it can be confused with.

First identify whether a setting refers to a protocol, a transport, or a client option, then enter the parameters provided by the server. Similar names do not necessarily mean interchangeable settings.

Connection types

Proxy protocols

Choose the right protocol in the client, then enter its authentication and security parameters. Protocol and transport are separate settings.

VMess

A proxy protocol in the Project V ecosystem that identifies connections using parameters such as a user ID. Configuration typically includes the address, port, user ID, and transport settings required by the server. Selecting VMess alone does not fill in the other fields.

VLESS

A streamlined proxy protocol commonly paired with transport security such as TLS or REALITY. Its user ID, transport, and security settings must match the server. REALITY is a separate configuration layer, not another name for VLESS.

Trojan

A proxy protocol that uses a password as its primary authentication parameter and is typically paired with TLS. When adding a server, check the password, destination address, port, and TLS fields. Do not infer the protocol from the port number; refer to the supplied configuration details.

Shadowsocks

A proxy protocol configured with parameters such as an encryption method and password. The client’s encryption method must match the server, and the password must be entered exactly. It is a different protocol from VMess and VLESS, and its share-link format is generally different too.

REALITY

A transport security scheme in the Xray ecosystem, commonly found in the security settings of VLESS connections. The client may ask for corresponding parameters such as the server name, public key, and short ID. REALITY does not replace the protocol type, and selecting a security option alone is not enough to configure the connection.

TLS

A transport-layer security mechanism that encrypts connections and verifies identity. Client options such as server name and certificate verification belong to this layer and should match the server deployment. TLS can appear in the same configuration as transports such as TCP or WebSocket.

Programs and runtime components

Cores & Ecosystem

Graphical clients manage configurations; cores handle the actual connections. Knowing the difference helps when interpreting errors and checking feature support.

Xray Core

The component that parses configuration and runs connections, transports, and routing rules in the Xray ecosystem. Graphical clients such as v2rayN provide the settings interface, while supported protocols and parameters also depend on the selected core. If a configuration fails to start, check both the client message and the core logs.

V2Fly

An open-source core project continuing the Project V ecosystem, part of a different core family from Xray. The two share concepts and some similar settings, but their feature and field support is not identical. Before migrating a configuration, confirm that the target core supports its protocols and settings.

v2rayN

A graphical client for Windows, macOS, and Linux that brings together server, subscription group, routing, and system proxy management. It is an interface, not a proxy protocol. If a connection fails, check the client fields, selected core, and system proxy status separately.

v2rayNG

An Android graphical client for importing servers or subscriptions and managing connections and per-app proxying. Desktop v2rayN instructions do not necessarily apply to the mobile interface. When importing the same configuration, check that the app supports its protocol and transport settings.

How connections carry data

Transports & Obfuscation

The transport determines how data moves over a connection. Paths, service names, and hostnames must match the server configuration.

TCP

A connection-oriented transport and a common option in client transport settings. Selecting TCP configures only one transport layer; it does not determine the higher-level protocol, such as VMess or VLESS. Check the port, security options, and server requirements separately.

WebSocket

A bidirectional transport used by some configurations to carry proxy traffic. Common client fields include a path and, when required by the configuration, a hostname. Even a one-character difference in the path can prevent the server from handling the connection as expected.

gRPC

A protocol framework that can be used as a connection transport. The client may show corresponding fields such as a service name. It is not a new server authentication method and must still be configured alongside the proxy protocol. Before using it, confirm that the client, core, and server support the transport settings.

SNI

The field used to specify the target hostname during the TLS handshake. In the client, it may be labeled “Server Name” or appear under transport security settings. The connection address and this name do not have to be the same; enter each according to the server configuration.

Where connections are routed

DNS & Routing

Routing rules choose an outbound route based on destination details. Whether a rule matches also depends on DNS resolution, rule order, and data files.

Routing rule

A matching rule that assigns an outbound route to a connection based on conditions such as its domain or IP address. Client routing settings usually offer preset modes and a way to add custom rules. When multiple rules are present, check their order and what happens when none match.

Traffic routing

A configuration approach that applies different handling to different destinations according to rules, such as sending specific domains through a particular outbound route. Traffic routing is not controlled by a single toggle; domain detection and rule priority also matter. When troubleshooting, first confirm that the connection reaches the client, then check which rule it matches.

GeoIP

A data category used by routing rules to match IP addresses by geographic region. It applies to IP addresses, not directly to domains as domain rules. Classification depends on the data in use and how recently it was updated, so results are not permanent.

GeoSite

A data category used by routing rules to match sets of domains, often alongside GeoIP in routing configuration. They match different things: GeoSite covers domains, while GeoIP covers IP addresses. Check the current data to see whether a domain belongs to a particular set.

Where configurations come from

Subscriptions

Subscriptions fetch configurations in bulk, while share links are generally used to import a single one. Successful import and a working connection are separate things to check.

Subscription URL

An address a client uses to fetch a set of server configurations, usually added under “Subscription groups.” Updating a subscription reloads data from that source; it does not change server parameters. A subscription URL may contain access credentials, so keep it as carefully as you would account details.

Subscription group

A client-side management unit that organizes server configurations by source. Assigning different names to each source makes it easier to identify what will be updated and filter the list. Switching groups changes the management view or selection scope; you still need to choose a specific server and check its connection settings.

Server profile

A common name for a single server connection entry in the client list, usually containing an address, port, protocol, and authentication parameters. It is not a standalone core or a fixed measure of network quality. Seeing an entry in the list only means the client has loaded its information.

What happens on your device

Client settings

Even when the client says “Connected,” check which settings are being used by the operating system, each app, and DNS resolution.

System proxy

A proxy endpoint provided by the operating system to apps that follow its system proxy settings. In the v2rayN tray menu, “Set system proxy” configures this endpoint, while “Clear system proxy” removes it. Some programs use their own network settings and may not follow the system proxy.

TUN mode

A connection mode that handles device traffic through a virtual network interface, with different coverage from the system proxy. Enabling it may require operating system permissions; check routing and DNS settings as well. TUN is not a proxy protocol and cannot replace authentication parameters in the server configuration.

FakeDNS

Under certain DNS configurations, returns a virtual address for a domain to preserve the association between that domain and subsequent traffic. The address is not the domain’s real DNS result. Whether to enable it depends on how traffic is intercepted and which routing rules are in use.

DNS leak

When a domain lookup that should use a designated DNS route is sent through a different one. This involves the DNS settings used by the app, operating system, and client, so the connection button alone cannot tell you whether a leak is occurring. When troubleshooting, first identify which program made the DNS request.

Real connection latency

A client test that measures response time by establishing an actual connection, unlike a test that only checks basic reachability. Results vary with the test target, network conditions, and timing. It reflects the response time during that test, not sustained transfer speed.