VPN beginners usually have questions about devices, data usage, speed, and connection methods. You do not need a complete networking theory course to get started, but it helps to understand the roles of the client, subscription, route, and protocol. The ten answers below follow the actual setup process: how the service reaches your device, followed by data usage, speed limits, split tunneling, DNS, and troubleshooting. Jump to the relevant question whenever an issue comes up.

What are a VPN service, client, subscription, and node?

These terms often appear together in the same interface, but they refer to different things. A VPN service provides available routes and connection credentials; a client is the connection tool installed on your device; a subscription is usually a service-generated address that delivers node details to the client; and a node is a specific entry or exit point available in the client’s list.

Seeing a list of regions after importing a subscription does not mean you are connected. You still need to select a node, start the connection, and grant the system proxy or VPN permission. Only traffic covered by the rules will then use the selected route. Subscription URLs may update node names, server parameters, or availability, so avoid copying nodes manually and leaving them unchanged indefinitely.

Name What it does Common beginner misconception
VPN service Provides account access, routes, and connection settings Buying the service automatically completes every setup step on the device
Client Reads configuration, creates the tunnel, and applies split-tunneling rules Every client supports every protocol and configuration format
Subscription link Distributes and updates node details for compatible clients Opening the link in a browser completes the connection
Node or route Determines the server and exit region used by your traffic A farther region is always faster
In short: The subscription is the configuration source, the client is the tool that applies it, and the node is the selectable path. If importing succeeds but access still fails, check whether the connection is active, whether the protocol is compatible, and whether the split-tunneling rules match.

Can I use the VPN on multiple devices at the same time?

Simultaneous connections depend on the specific service plan, not on a universal VPN limitation. Computers, tablets, and routers can each be separate connection endpoints; multiple configurations in one client do not count as multiple devices. BiliVPN plans support use on an unlimited number of devices, making it practical to import the subscription separately on your own devices.

Each device still generates its own traffic and may use a different route. If devices share the same data allowance, computer downloads, TV streaming, and tablet updates all count toward the same account. Unlimited devices does not duplicate bandwidth; when several devices transfer data at once, the home network, router performance, and selected route can all become shared bottlenecks.

Take extra care when importing a subscription on a public device. The subscription URL may contain access credentials, so do not share it publicly, post screenshots, or leave it on a device you no longer use. After changing devices, delete the configuration from the old client and manage the subscription through the update method provided in the service panel.

How is VPN data usage calculated?

VPN usage is generally based on the amount of data transferred through the route. Browsing downloads page resources, sending files creates upload traffic, and video buffering, software updates, cloud-drive sync, and background refreshes can all continue transferring data. Whether uploads and downloads are both counted depends on the billing description and dashboard records for your plan.

A browser may appear idle while the device continues working in the background. System updates, photo sync, message-attachment preloading, and app-store downloads can all run without obvious foreground activity. If usage is higher than expected, check the operating system’s data-usage statistics and investigate by app instead of watching only the page currently open.

  • ✅ Check whether system updates, cloud drives, or photo sync are transferring data in the background.
  • ✅ Check whether the video platform has automatically selected a higher quality.
  • ✅ Confirm which apps actually use the VPN route in split-tunneling mode.
  • ✅ Compare the client statistics with the service dashboard’s reporting period and measurement method.
  • ❌ Do not assume that minimizing the client window has stopped the connection.

Is a slower connection caused by throttling?

A speed drop does not necessarily mean the service is throttling you. After connecting to a VPN, data usually travels through an additional route and is encrypted, encapsulated, and forwarded. Physical distance, congestion at international exits, transit quality, server load, local Wi-Fi, client protocol implementation, and restrictions imposed by the target website can all affect the result.

You cannot determine throttling from a single speed test. A more reliable approach is to test a direct connection and several routes in the same region under similar network conditions, then compare browsing, downloads, and video playback. If only one website is slow, the issue may be with that service or its content delivery network. If every node is slow, check the local network and client settings first.

Do not run cloud sync or downloads during a speed test, and do not switch nodes while leaving the old connection active. After switching routes, wait for the client to reconnect before reopening the target app. Browser caching can make a page appear to load quickly, but it does not prove sustained transfer capacity.

Order of checks: Rule out the local network and background tasks first, then compare different routes in the same region, and finally check whether the target website is the only service behaving abnormally. Only consistent, repeatable results are useful for assessing route conditions.

Does the VPN need to stay on all the time?

Whether to keep it on depends on what you are doing. Stay connected when accessing services that require a particular exit region, using public networks, or keeping selected apps inside an encrypted tunnel. If you are using local services, performing latency-sensitive local-network tasks, or do not want background sync to consume plan data, disconnect when needed or use split tunneling.

With an always-on setup, the important question is what happens after a disconnect. Some clients offer a kill switch that blocks connections meant to use the VPN instead of letting them fall back directly to the local network. Understand its scope before enabling it: incorrect rules can temporarily block local devices, printers, or local websites.

Mobile devices are also affected by system power-saving policies. When an app moves into the background, the system may pause its connection process; switching between wireless networks and other access methods can also trigger a reconnect. For a stable always-on connection, allow the client to run in the background and check whether the system restricts its network activity.

How do I choose between Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC?

These names refer to different proxy protocols or transport approaches, and they cannot be ranked simply as newer or better. Shadowsocks has a relatively simple structure and broad client support. VMess and VLESS are common in clients that support multiple transport combinations. Trojan typically uses a transport method resembling ordinary TLS traffic. Hysteria2 and TUIC focus on UDP-based transport and may perform differently in particular network conditions.

Protocol choice is first constrained by client compatibility. If the server provides a configuration but the client does not recognize its fields, importing it may produce errors, skip the node, or fail to connect. You should also consider whether the current network permits the required transport. Some networks handle UDP poorly, causing UDP-dependent options to time out; switching to another protocol provided by the service is usually more reliable than repeatedly changing unknown parameters.

Beginners do not need to guess encryption parameters, transport layers, or server names. Start by importing the subscription provided by the service and using its recommended client. Compare protocol differences only after confirming that the client version, system permissions, and subscription updates are all working normally.

Protocol or approach What to watch Common troubleshooting focus
Shadowsocks Configuration simplicity and client compatibility Whether the encryption method matches client support
VMess / VLESS Transport combinations and the number of subscription fields Transport layer, TLS, and server-name settings
Trojan Whether the TLS connection matches the certificate name System time, server name, and certificate validation
Hysteria2 / TUIC UDP network quality and client version Whether the current network restricts UDP traffic

How do I import a subscription link into a client?

The standard process is to copy the subscription URL from the service dashboard, find “Import from URL,” “Add subscription,” or a similar option in a compatible client, paste the URL, and run an update. After the import succeeds, select a node and enable the system proxy or VPN mode. Button labels vary between clients, but the workflow is the same: obtain the configuration, select a node, and establish the connection.

Treat the subscription URL as private credentials. Do not paste it into an online conversion site or send it to a public group. If the client supports only local files while the service provides a URL, consult the service’s client instructions instead of using an untrusted format-conversion tool.

  1. Copy the complete subscription URL from the service dashboard and check that there are no extra spaces at either end.
  2. In a compatible client, choose the option to add a subscription by URL instead of adding individual nodes manually.
  3. Run a subscription update and check whether regional and route names appear.
  4. Select a route, start the connection, and grant network permission when prompted by the system.
  5. Open an IP-check page and confirm that the exit region matches the route you selected.
  6. When nodes change later, update the subscription before deciding that a route has stopped working.

What is the difference between IEPL, transit, and direct routes?

A direct route usually connects your network straight to a remote server. Its path is simple, but quality depends more heavily on the local carrier and the condition of the public international network. A transit route first connects to a nearby entry point and then uses a transit network to reach the exit region, with the goal of improving the first segment or the international path. IEPL is an enterprise-grade international private-line model that uses dedicated transport between regions, with routing logic different from an ordinary public-internet connection.

A route name describes the path type; it does not guarantee higher speed at every time and location. Local access quality, entry-point location, exit load, and the target website’s network still affect the experience. Choose a target region first, then compare direct, transit, and private-line routes within that region instead of assuming that “private line” is always the right option.

On-demand video depends more on sustained transfer stability, live meetings and interactive tasks depend more on latency consistency, and ordinary webpages are more easily affected by DNS and the distribution of page resources. Choose a route for the task rather than relying only on the highest number from a single speed test.

What is a DNS leak, and how can I check for one?

DNS translates domain names into network addresses. After connecting to a VPN, a DNS leak can occur when domain lookups are still handled by DNS servers on the local network while the actual web traffic uses a different exit path. This can reveal the resolver used by the local network and may create conflicting regional signals.

When checking, observe the exit IP and DNS results together. If the exit has changed but DNS still consistently points to a local network provider, review the client’s DNS mode, the scope of its system proxy, and the browser’s encrypted-DNS settings. Browsers may use their own resolution strategy, so changing the operating system DNS does not necessarily cover every request.

A test page listing resolvers in different regions does not automatically indicate a leak. Public DNS services may use distributed nodes, and the displayed location does not necessarily mean the request traveled directly from the local network. Focus on whether resolution matches the client configuration and whether the results change in an explainable way when the VPN is disconnected.

Which should I use: split tunneling, global, or rule mode?

Global mode usually sends most network requests through the selected route. It is useful for temporarily checking whether rules are missing target traffic, but it may also send local websites, LAN services, and background updates through the VPN. Rule mode determines the destination by domain, network address, application, or rule set, making it better suited to daily use. Split tunneling is the general term for choosing paths conditionally in this way.

Rules are not permanently correct lists. Websites can change domains or call new content-delivery addresses, while apps may place sign-in, images, and video on different domains. When the homepage opens but its content fails to load, a common cause is that related domains do not match the same rule.

Target service main domain → VPN route
Target service resource domain → VPN route
Local websites and LAN → Direct connection
Unmatched requests → Follow the client’s default rules

When troubleshooting split tunneling, briefly switch to global mode for comparison. If global mode works but rule mode does not, focus on rule matching, DNS resolution, and app bypass settings. If both modes fail, continue checking the node, protocol, and local network. Restore the rule mode suited to daily use after testing.

Mode recommendation: For daily use, choose a rule mode that you can understand and maintain; use global mode for comparison during troubleshooting. The more complex the rules, the more often you should check for omissions and conflicts.

How do Windows, macOS, Android, and iOS clients differ?

Every platform can establish a VPN or proxy connection, but system permissions and background behavior differ. Windows clients often provide both a system-proxy mode and a virtual-network-adapter mode. The former mainly affects apps that follow the system proxy, while the latter can cover more network traffic. macOS has a similar distinction and may request permission for a network extension or VPN configuration.

Android clients can usually decide which apps enter the VPN and are also easily affected by battery optimization. iOS clients rely on the VPN framework provided by the system; the first connection usually requires adding a VPN configuration. Background reconnection and on-demand behavior are controlled jointly by the system and client. Different button labels across platforms do not mean the subscription content is different.

Routers are a separate use case. They can let connected devices share a route, but configuration, performance, and split-tunneling capabilities depend on the router’s operating system. If you only need access on everyday devices, starting with the officially recommended desktop or mobile client usually makes troubleshooting easier.

  • ✅ After connecting on Windows, check whether the client is using system proxy mode or virtual-network-adapter mode.
  • ✅ On macOS, confirm that the required network extension or VPN configuration is allowed.
  • ✅ On Android, check whether battery optimization pauses the client in the background.
  • ✅ On iOS, after switching networks, check whether the client completes the automatic reconnection.
  • ❌ Do not assume that clients with the same name have exactly the same features on every platform.

What order should I follow when a connection fails?

The biggest troubleshooting mistake is changing several settings at once. If you change the protocol, DNS, route, and split-tunneling rules together, even a successful recovery will not tell you which adjustment helped. A better approach is to keep the client and network environment fixed, change one variable at a time, and record whether the error occurs during import, connection, or access.

If the subscription will not import, first confirm that the URL is complete, the client is compatible, and the device time is correct. If nodes import but the connection times out, update the subscription and try another route in the same region. If the client says it is connected but webpages will not open, check the system proxy, virtual-network-adapter permissions, DNS, and split-tunneling rules. If only the target app fails, check whether it bypasses the system proxy or retained an old network session.

  1. Confirm that the local network can access common websites normally when the VPN is disconnected.
  2. Update the subscription so you do not continue using an old node configuration that may have changed.
  3. Select another route in the same region and compare it without changing any other settings.
  4. Restart the connection, then fully close and reopen the target app.
  5. Check the client log for timeout, DNS, certificate, or permission messages.
  6. If the cause is still unclear, send support the client version, system type, route name, and error message.

When submitting an issue, do not publicly send the complete subscription URL or password. Mask credentials in screenshots and leave only the client version, error details, and route name visible. BiliVPN offers 200+ routes across 90+ countries and regions, supports unlimited devices, and provides a 7-day no-questions-asked refund. If a route does not suit the current network, try another route in the same target region for comparison.