This VPN FAQ is for readers new to international routes, subscription links, and proxy clients. Instead of listing jargon, it answers the issues that most often cause trouble: why websites remain inaccessible after a client says it is connected, how to use one account across multiple devices, when monthly data resets, why speeds vary, and when to turn a connection on or off.

Start with one basic point: a VPN or proxy service is only one part of the network path. Your experience is also shaped by the local network, ISP routing, client settings, protocol behavior, the destination website, and the time of day. When speeds change, do not immediately blame a particular node or change every setting at once. Check in this order: local network, client status, route, split tunneling and DNS, then the destination service.

What are VPNs, proxy clients, and subscription links?

In everyday conversation, people often use “VPN” to refer collectively to VPNs, proxy protocols, route services, and clients, but they are not technically identical. A VPN typically handles device traffic through a virtual network interface. A proxy may handle only the system proxy, browser requests, or connections selected by rules. The result depends on whether the client uses system proxy mode, TUN mode, or an in-app proxy configuration.

A client is a connection tool that runs on Windows, macOS, Android, iOS, or Linux. It reads node details, establishes an encrypted connection, applies split-tunneling rules, and forwards matching requests through the selected route. The route service provides connection parameters and available nodes; the client turns those parameters into an actual network path on the device. Neither replaces the other.

A subscription link is a configuration address that compatible clients can read. It usually contains node names, protocol parameters, and an update endpoint. After importing it, the client builds a node list. When the service adjusts its routes, you can update the subscription instead of editing each node manually. Treat the subscription link as part of your account credentials: do not publish it, share screenshots containing it, or give it to untrusted software. If you suspect it has been exposed, update the credential in the user panel and import it again.

First, distinguish between “signing in” and “importing a subscription.” Sign in to the ijvpn user panel to manage your plan and access client and subscription information. Import the subscription link into a compatible client to create connectable routes on your device. No email address is required; keep your username and password safe.

How should common protocols be understood?

A protocol determines how the client and server handshake, authenticate, encrypt, and transport data, but the protocol name alone does not determine speed. The same protocol can perform differently across networks, server configurations, and client implementations. Beginners usually do not need to chase protocol names; using a server-recommended configuration that the client fully supports is the better starting point.

Protocol Key characteristics What to watch for
Shadowsocks An encrypted proxy protocol with straightforward configuration and broad client support The encryption method must match the server; older clients may not support newer configurations
VMess Common in the V2Ray ecosystem, with authentication and transport settings The transport layer, security layer, and path parameters must all match
Trojan Usually establishes connections with TLS and depends on correct domain and certificate settings System time, certificate validation, and server-name settings can affect the handshake
VLESS Uses a relatively streamlined authentication design and does not provide a complete encryption layer by itself Usually needs to be combined with TLS or another secure transport method
Hysteria2 Built on QUIC and UDP, with an emphasis on transport control in complex networks If the local network restricts UDP, the handshake may fail or require a fallback
TUIC Also built on QUIC and UDP, with support for multiplexed connections and congestion control The client, server, and current network must all support UDP correctly

If an Hysteria2 or TUIC route cannot connect on the current network while a TCP-based route works normally, the cause may be UDP restrictions on a hotel, company, or public network. Switching protocols is more effective than repeatedly reinstalling the client. Conversely, when UDP works normally and the network is noticeably unstable, these protocols may show different transport characteristics.

Protocol compatibility also depends on the client version. A successful configuration import does not mean every field was recognized correctly; an older version may ignore new parameters, leaving the node visible but unable to connect. During troubleshooting, update to the client version provided or recommended by the service, then update the subscription again. This helps distinguish client parsing issues from route failures.

What is the difference between direct, transit, and IEPL routes?

Route names describe, in broad terms, how data travels from the local network to an overseas exit. A direct route usually means the device connects to an overseas server through the public internet. The path is simpler but more exposed to cross-network routing and international-exit congestion. Direct does not necessarily mean slow; when the public route from the local network to the server is suitable, it can work well for ordinary web and file access.

A transit route first connects to an entry point closer to the user or one with more stable routing, then forwards traffic to the destination region. Transit can avoid some poor public routes, but it adds another forwarding step. Entry quality, the link from entry to exit, and the exit itself all affect the final experience, so “transit” does not mean fast at every hour.

IEPL is a type of international Ethernet private-line service. In route services, it generally means that the link between the entry point and overseas exit uses a relatively independent transport path, unlike a direct route that relies entirely on the public internet. The connection from your device to the entry point and the path from the overseas exit to the destination website may still use other networks. A private line improves control over a specific part of the path; it does not mean the entire access process leaves the public internet.

Beginner route-selection takeaway: For everyday browsing, choose a route whose location matches the destination service. For video, meetings, or sustained downloads, prioritize long-term stability. When performance changes in the evening, compare direct, transit, and private-line routes in practice instead of judging by name alone.

Why does speed change after connecting?

After connecting, data usually travels through additional encryption, encapsulation, and forwarding steps, so different performance is normal. Web-page loading, video buffering, file downloads, and live meetings also measure different things. Browsing is more affected by DNS and connection setup; downloads depend more on sustained throughput; meetings are more sensitive to jitter, packet loss, and path stability.

Latency in a route list is useful for initial filtering, but it does not fully represent real-world speed. A low-latency node may not have suitable exit bandwidth for the task, while a slightly higher-latency node may be more stable during sustained transfers. The client’s test request and the destination website’s request may also use different networks, so a single test should not be treated as a long-term conclusion.

Check speed issues in this order

  1. Pause large-file syncing, system updates, and other tasks that continuously use bandwidth to see whether the issue comes from the local device.
  2. Disconnect the route and test the local network. If ordinary websites are also unstable, troubleshoot the router, wireless network, or upstream network first.
  3. Reconnect to the current node to rule out a temporary handshake issue or a network transition.
  4. Choose another route in the same region and observe whether the issue affects one node or the region’s path as a whole.
  5. If supported by the client, switch transport protocols, paying particular attention to whether the current network restricts UDP.
  6. Check split-tunneling mode and confirm that the speed-test tool, browser, and destination app are actually using the expected route.
  7. Update the subscription and client to avoid continuing to use outdated node parameters.

Keep test conditions consistent: use the same device, network, and destination service, and reduce background tasks. Do not switch nodes, change DNS, and adjust the system proxy at the same time. When multiple variables change together, it is difficult to identify the real cause even if the issue disappears.

How is data usage calculated across multiple devices?

ijvpn supports simultaneous connections on an unlimited number of devices, making it suitable for computers, tablets, and other everyday devices. Unlimited devices does not mean each device has separate data. Devices connected to the same account share the available data in the applicable plan. System updates, cloud syncing, video playback, and automatic app downloads all count toward actual transfer usage.

The most common multi-device issue is unnoticed background usage, not the number of connections. For example, cloud backup on a computer can make the remaining data fall faster for every other device; extended high-bitrate playback on a tablet can also reduce the shared balance. When investigating unusual usage, check each device’s system data statistics and temporarily disable automatic updates, photo syncing, and large-file backups.

Even when using one account across your own devices, avoid sending the subscription link directly to other people. Once the address leaves your control, it becomes difficult to know which devices are updating configuration or consuming data. When setting up a new device, copy the link again from the user panel and transfer it between your own devices through a trusted method.

When does monthly data reset, and how are data packs used?

Monthly plans and data packs use different billing models. The allowance in a monthly plan resets according to the subscription cycle; do not assume that the start of the calendar month is every account’s reset date. Use the current cycle and expiration details shown in the user panel as the accurate reference. If the allowance runs out early, wait for the cycle to reset or choose another option based on your needs.

Data packs are better suited to variable usage, such as travel or occasional tasks. ijvpn data packs do not expire, so unused data can be retained; this differs from the cycle-based reset of a monthly plan. Before choosing, decide whether your usage is ongoing or intermittent rather than judging only by the data needed for one transfer.

Data-usage tip Browsing text pages uses far less data than continuous video playback, while system updates and cloud syncing may run in the background. The used-data figure in the panel is a better way to judge plan fit than subjective time spent online.

How do you import and update a subscription link?

Button names vary slightly between clients, but the basic process is the same: get the subscription details from the ijvpn user panel, then find “Add subscription,” “Import from URL,” or a similar option in a compatible client. Paste the link and run an update. Once the node list appears, choose a route and start the connection.

Complete first-import checklist

  1. Make sure the device date and time are accurate. TLS certificate validation relies on system time, and a clock offset can cause secure connections to fail.
  2. Copy the complete subscription link from the user panel rather than typing it manually or omitting the ending.
  3. Create a new subscription in the client instead of pasting the link into a single-node address field.
  4. Run a subscription update and wait for the node list to finish parsing.
  5. Choose a node suited to your task, then enable the system proxy or TUN mode.
  6. Open an ordinary webpage to verify the connection, and check whether the destination app follows the system network settings.

If the nodes do not change after updating the subscription, first check whether the client shows an update time or error message. Some systems restrict background network access, so automatic updates may not run; opening the client and updating manually usually makes the result easier to verify. If the client reports an unsupported format, check that you are using a compatible client rather than opening the subscription link as a webpage.

Deleting an old subscription and adding it again can resolve some cache issues, but it should not be the first step. Updating the client, manually refreshing the subscription, and reviewing the error message helps preserve existing split-tunneling rules and preferences. If reimporting is genuinely necessary, export any rules you wrote yourself first so they are not lost.

Why do clients behave differently across platforms?

Windows clients commonly use system proxy or TUN mode. System proxy mode depends on apps following the system setting, and some may bypass it. TUN mode takes over a broader range of traffic through a virtual network interface but usually requires appropriate system permissions. If a browser works while a desktop app does not, first check whether the app supports the system proxy, then decide whether to use TUN.

On macOS, apps that do not follow system settings can likewise bypass the proxy. Clients using a network extension or virtual interface generally cover more traffic, but the first activation requires permission in system settings. If the connection fails after a system update, check whether the network extension is still allowed.

On Android, the system VPN interface lets the client handle most app traffic, but battery-saving policies may prevent it from maintaining a background connection. If it disconnects frequently after the screen locks, check battery optimization and background-running permissions. Some apps may also use their own DNS or network implementation, so review the client logs together with split-tunneling rules.

iOS clients rely on the network-extension capabilities provided by the system. When switching between Wi-Fi and cellular data, the existing connection may need to be established again. If the status bar shows a connection but the destination app does not recover, disconnect and reconnect first. When importing a subscription, also confirm that the client supports the protocol types included in it.

On Linux, differences come mainly from the distribution’s network stack, desktop environment, and command-line tools. Setting proxy environment variables in a terminal does not automatically cover every graphical app; enabling a browser proxy does not make the package manager use the same path. For broader traffic handling, use the client’s TUN capability and check that routes and DNS settings update correctly when the connection starts.

What is a DNS leak, and how should you check for one?

DNS translates domain names into network addresses. A DNS leak generally means that traffic follows the expected route while domain lookups are still handled by the local network’s resolver, or that some queries bypass the path configured by the client. This can produce results associated with a different region and expose the queried domains to the local network.

Do not check only the public exit address. Also identify which resolver handles DNS requests, whether IPv4 and IPv6 follow the same policy, and whether the browser has enabled its own encrypted DNS. Browser DNS, operating-system DNS, client-side remote DNS, and router DNS may all coexist; conflicting settings can produce seemingly random results.

Ways to reduce DNS path conflicts

A DNS leak and a website that will not open are not the same problem. A resolution failure appears as an inability to find the domain, while a route connection failure may also involve a handshake timeout or affect every destination. When reading client logs, first determine whether the failure is at the resolution, connection, or destination-server response stage.

How should you choose global mode, rule-based routing, or direct mode?

Global mode generally sends most traffic through the current route. It is useful for temporarily checking whether an app was missed by the rules, but it also sends local websites and LAN services through an additional path. Rule-based routing uses domains, IPs, app processes, or rule sets to decide between proxy and direct access, making it better for everyday use. Direct mode is typically used to pause proxy forwarding or troubleshoot the local network.

A sensible routing policy should begin with a clear purpose. Keep access to local services, printers, and LAN storage direct; send destinations that need international routes through a node. More rules are not always better. Unknown or outdated rule sets may misclassify domains, causing login redirects, images, or verification requests to use different exits.

One website may call several domains at once. If the main page uses the route while static resources connect directly, or the login API and page use different exits, loading may be incomplete. If you see text without images or a repeating login loop, temporarily switch to global mode as a test. If that fixes the issue, the problem is more likely the routing rules than a completely unusable node.

Split-tunneling troubleshooting principle Use temporary global mode only to locate the issue. Once you identify a missed domain or app, correct the rules and return to need-based routing so unrelated traffic does not take a longer path permanently.

Should a VPN stay on all the time or be enabled only when needed?

Whether to keep it on depends on the network environment and your goal. On unfamiliar public networks, maintaining an encrypted connection can reduce direct exposure of traffic on the local path. When using international websites, remote collaboration tools, or cross-border services continuously, keeping the same exit can also reduce session changes caused by frequent switching.

When accessing LAN devices, local low-latency services, or only trusted local networks, you can route those requests directly with split tunneling instead of shutting down the entire client. Need-based use is not about repeatedly toggling the client; it is about sending traffic that needs international routes through a node while keeping local activity on a suitable path.

Banks, payment services, enterprise systems, and streaming platforms may apply additional checks based on exit region and session state. Switching nodes changes the public exit, and frequent changes between regions may trigger another sign-in. Before an important task, choose a region suited to the purpose and keep the connection stable. If the destination service explicitly requires a local network, follow its rules.

Connected but unable to access anything? Troubleshoot step by step

“Connected” in a client usually means that the local proxy or virtual interface has started. It does not necessarily mean the remote handshake succeeded, nor does it guarantee that the destination app is using that path. Separate local startup, remote connection, DNS resolution, and app routing during troubleshooting.

  1. Confirm that the local network itself works by disconnecting the client and trying an ordinary webpage.
  2. Update the subscription and switch to another node in the same region to rule out a temporary configuration or route issue.
  3. Review the client logs for DNS failures, connection timeouts, certificate-validation errors, and unavailable UDP.
  4. Confirm that the system proxy or TUN mode is actually enabled, and check whether the destination app bypasses the system proxy.
  5. Temporarily switch to global mode. If access returns, inspect the split-tunneling rules.
  6. Close other software that changes the network path at the same time to prevent virtual interfaces, proxy settings, or DNS configurations from overriding one another.
  7. Restart the client and reconnect. If the system networking components remain abnormal, restart the device and router as well.

If only one website is inaccessible while other international websites work, the cause is more likely a destination-site restriction, regional detection, DNS cache, or a missing routing rule. If every node fails to handshake, focus on local network restrictions, system time, client version, and protocol compatibility. If only UDP protocols fail, try a TCP-based route first; there is no need to reinstall the system immediately.

Other questions beginners often ask

Do I need an email address to create an account?

No email address is required; a username and password are enough. Save your login details yourself so forgotten credentials do not interfere with account management.

Are farther-away nodes always slower?

Physical distance affects propagation time, but it is not the only factor. ISP routing, cross-network quality, entry and exit load, the protocol, and the destination website can all change the result. A node near the destination region is a sensible starting point, but actual task performance remains the deciding factor.

Why does the browser work while other apps cannot connect?

The browser may follow the system proxy while other apps use their own network settings or connect directly. Check the app’s own proxy options, or use TUN mode if the client supports it, then confirm that the split-tunneling rules include the app.

Does a failed subscription update mean my account is invalid?

Not necessarily. A failed update can also result from the local network, an incomplete link copy, an outdated client, or an incompatible subscription format. Check the panel status and the client’s error message before deciding whether to import it again.

Why does a website still show my old region after I switch nodes?

The website may be reading an old session, cache, location permission, or a request still handled directly by a routing rule. After confirming that the exit has changed, reopen the app, clear the relevant site cache, and check that the domain is actually using the selected route.

Do I need to update the subscription every day?

There is no need to update it mechanically or repeatedly. Update when nodes change, connections become abnormal, or the service indicates a change. If the client supports reliable scheduled updates, you can enable them, but still avoid giving the subscription link to untrusted software.

Final checklist for beginners

For a first setup, confirm that the client supports the subscription’s protocols, then import the complete link and update the nodes. Use rule-based routing for everyday activity and switch to global mode only temporarily when locating a rule issue. When speeds are abnormal, check the local network and background tasks before comparing routes in the same region and different transport methods. When devices share an account, remember that they share its data and watch for system updates and cloud syncing.

When connection status and actual access do not match, check the remote handshake, DNS, system proxy or TUN mode, app routing, and destination service separately instead of relying on the client icon. Keep your username, password, and subscription details safe, update the client regularly, and change only one variable at a time during troubleshooting. This avoids most repeated trial and error for beginners.

Key takeaway: No route or protocol performs identically on every network. Reliable use depends on understanding what the client takes over, choosing a path suited to the task, and troubleshooting speed, DNS, routing, and device differences in a structured order.