BLOG · 08-08

Config, Proxy, Direct: pick, then connect

A lit switch only means the system tunnel is up.

VPN in the status bar only means the system tunnel is up. It does not guarantee this site should go through the tunnel, or that the node you selected is still alive. A lot of people treat “lit” as success, then reinstall, change ciphers, and twist five switches at once. The cheaper move is to separate the three stances, then flip in a fixed order.

The order is: select a node, pick a mode, then flip the switch. Flip with nothing selected and you may connect an old row—or nothing. A successful import also doesn’t mean the currently selected row works. Open the subscription and tap Update, or pull down on the home list; connectivity-test a few rows and look at latency and handshake, not the peak speeds in ads. Skip timeouts and failures. Tap a row that can handshake, confirm it’s selected, then talk mode.

Config: where daily use should stay

Config splits by rules: tunnel what should tunnel, leave the rest local. Daily default should be this. It saves battery and is less likely to break local apps, banking, LAN printing, and system updates. Many subscriptions ship rules. Two maps stacked is a common reason things get “slower the more you tweak.” Touch settings only after you can get online stably; if the subscription already brings rules, watch for a few days first.

A site that shouldn’t be Direct but is: switch to Proxy to verify. If it opens, go back to Config, add a rule, and write down what you changed so you can roll back. Don’t live in global for one site. How to add a rule and how to fill DNS are in tutorial section 06. Prefer the DNS your provider wrote in their notes. Empty or following the system is usually safer than a random public DNS. A bad fill makes split decisions wrong: switch on, this site still won’t come out.

Proxy: for debugging, not the default

Proxy is close to global—traffic goes into the tunnel when it can. It’s good for two jobs: confirm the node itself works, and confirm a domain was missed by rules. Don’t start here as a beginner and stay. All-day Proxy shoves video, system updates, and local services down one node—slow and power-hungry. Heat is often a bad node or long global use, not a “sick client.”

When debugging, change only this: Config to Proxy, and see if the problem in front of you disappears. If it does, go back to Config and add a rule. If it doesn’t, switch to a node you just tested, or give the node name and approximate time to the provider. Don’t turn on MITM, randomly change ports, or stack several encrypted DNS setups while you’re in Proxy.

Direct: for comparison—and you can stay here

Direct is turning the instrument off. It answers a more basic question: can the phone itself get online. A Wi-Fi captive portal, a carrier outage, or airplane mode left on will make people think Shadowrocket broke. Switch to Direct first. If Direct can’t open anything, fix the network before you edit the client.

When you’re done you can stay on Direct. You don’t have to leave it on all day. A Home Screen widget can only flip the switch quickly; it cannot replace “pick a node, then a mode.” If it suddenly fails after you change Wi-Fi or cellular, test a few nodes first, then check permission.

What counts as connected

You should be able to say all three: the switch is on; latency is acceptable; you know whether this app should tunnel or go Direct. Missing one: compare on Direct, then change nodes—don’t start by changing ciphers. If only some apps fail, verify with Proxy the same way, then edit rules. Don’t reinstall first.

Especially power-hungry: switch back to Config, use Direct when idle, and avoid nodes that clearly drop packets. Broken after an iOS update: delete the old VPN configuration and allow again from the app. UI or signature doesn’t look official: delete it and reinstall only from the App Store. Don’t fix a crack.

Matching steps are in the tutorial, sections 05 and 08. Meanings are in the glossary. No official app yet? Start at download.

Change one thing at a time so you can roll back

The worst habit when you can’t connect is changing mode, swapping nodes, editing DNS, turning on MITM, and reinstalling at once. Five things stacked, you can’t tell which one worked, and you can’t return to “it worked a minute ago.” The right layers: Direct first to see the phone itself; then confirm VPN permission is still there; then update the subscription, switch to a node you just tested, and put the mode back on Config; still failing, switch to Proxy once for a contrast. Proxy works: edit rules. Proxy fails: give the symptom to the provider, instead of twisting more advanced switches in the client.

MITM, IPv6, UDP, and DoH each have a use, but they almost never save a dead node or an expired subscription. Those two only go to the provider. Treating the repair bay as the default config only makes the next debug harder to read. Get the three stances stable first, then consider those switches—and don’t turn several on at once.

Pick a node, pick a mode, then flip the switch. Change one thing at a time.