To set up a Windows VPN, follow this order: get the client → import your subscription → choose a route → connect and verify → configure startup. First make sure you can connect manually, then set up automatic startup. Otherwise, after a restart, seeing the client icon won’t tell you whether the route is actually active. This guide covers where to find each setting, what a successful setup looks like, and how to troubleshoot problems.

Before you begin: get the client and your subscription link

Get the Windows client and subscription link from the service’s account dashboard. The client is the program that runs on your computer; the subscription link is an address the client uses to retrieve route configurations. It isn’t a regular webpage to open in your browser, or the name of a specific route. VPNTF users can sign in and visit the client download page, then follow the instructions in the dashboard to get the configuration. Use the installer and subscription link shown in your own account.

Don’t put your subscription link in public documents or screenshots. Anyone who has the link may be able to retrieve your route configuration. To move your setup to another computer, copy the link from your dashboard again instead of searching old chat messages. VPNTF doesn’t require an email address to create an account. Keep your username and password safe, and don’t share them along with your subscription link.

  • ✅ You’ve downloaded the Windows client from your account dashboard and can locate the installer.
  • ✅ You’ve copied the complete subscription link without adding spaces or other text at either end.
  • ✅ You know where to find the dashboard so you can check for configuration updates later.
  • ❌ Don’t import an unfamiliar configuration file you found online as your own subscription.

Install the Windows client and check that it’s running

Open the installer you downloaded and follow the prompts. If Windows asks for permission, check the program’s source and file name before allowing it to proceed. Some clients also request system permissions to install a virtual network adapter. This component may be needed for certain traffic-capture modes, depending on the client and connection mode you choose. Don’t treat every permission prompt as proof that the connection is working.

After installation, open the client from the Start menu. You should see its main window or an icon in the taskbar’s notification area. Some clients keep running there after you close the window. If double-clicking the icon doesn’t open another window, expand the notification area rather than reinstalling the client. If the program won’t open at all, check that you downloaded the Windows version and completed installation, then review any error message from Windows.

Client names and button layouts can change between versions. Look for an option such as “Subscription,” “Configuration,” or “Import from URL”; the interface doesn’t need to match an old screenshot exactly. For the first run, leave the connection settings at their defaults. Once you’ve verified the basic connection, you can adjust split tunneling, system proxy settings, or startup behavior. This makes problems easier to pinpoint.

Import the link, update it, and choose a route

In the client’s subscription manager or configuration import screen, choose an option such as “Import from URL,” paste in the subscription link, and save it before updating. A successful import usually adds routes to a selectable list. If you see a subscription name but no routes, check whether you also need to select “Update subscription.” Some clients require you to save before updating; others fetch the configuration as soon as you paste the link. In either case, check that the routes actually appear in the list.

  1. Open subscription management, paste the complete link, and save it. Don’t enter it in a field for an individual route address.
  2. Update the subscription, wait for the client to finish retrieving it, then return to the route list and check the results.
  3. Choose a route in a region that suits the destination website and is supported by your client, then set it as the current route.
  4. Turn on the connection and wait for the status to show connected before testing websites and exit information.

Subscriptions, protocols, and route types are different things. A subscription distributes configuration. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are protocol names you may encounter in client ecosystems; whether a client can read a particular configuration depends on its supported protocols. “Direct,” “relay,” and “IEPL” describe a route or its transport—not an import option—and the name alone doesn’t tell you how it will perform. If the client says the configuration format isn’t supported, first check which client and import method the dashboard recommends instead of changing protocol fields at random.

What you see What to check first Next step
Subscription saved, but the list is empty Check whether the link is complete and whether you updated the subscription Copy the link from your dashboard again, then update the subscription
Routes are listed, but none connect Check whether the current route is compatible with the client Try another available route and check the client’s error message
Shows connected, but websites won’t load System proxy, split tunneling rules, and the destination domain Test a simple webpage first, then check settings one at a time
The route list is out of date after a restart Check whether the subscription needs a manual update Open the client and update it. Starting on boot does not update the configuration

When choosing a region, first check the destination service’s regional requirements, then consider connection stability. Use the route list to see regions and route types. Don’t treat one fast page load as a guarantee for every time of day; your local network, the destination website, and the current route can all affect performance.

How to verify your connection and choose split tunneling settings

A “Connected” status only reflects the client’s local state. Next, verify that traffic is actually using the route. Leave the connection on, visit the IP check page, and note the exit information. Then disconnect, refresh the page, and compare the results. If the information doesn’t change as expected, check the client’s system proxy setting and whether your browser has its own proxy enabled. Browser extensions, other networking tools, and old system proxy settings can also affect the result. Change one setting at a time while troubleshooting.

System proxy mode usually routes traffic from apps that follow the system proxy settings, but it doesn’t automatically cover every program on your computer. A virtual network adapter or TUN mode may capture more traffic, but requires client support and the relevant permissions. Split tunneling’s “rule mode” routes traffic according to domain or destination matches, while “global mode” attempts to route all traffic within the mode’s scope through the selected route. “Global” is still affected by the client mode, app behavior, and system network settings, so verify the results rather than assuming it covers everything.

For your initial setup, start with the client’s recommended default rules and try opening the destination website. If it doesn’t work as expected, temporarily switch to global mode for comparison. If global mode works but rule mode doesn’t, check domain matching and split tunneling rules. If neither works, focus on the route connection, system proxy, and local network. After comparing, switch back to the mode that fits your everyday needs; there’s no need to keep temporary troubleshooting settings.

How to tell it’s set up: The route connects, the destination website loads, and the IP check shows the expected exit information for your selected route. If you also need to verify the DNS path, run a separate DNS test. A “Connected” status in the client shouldn’t be your only check.

Set up startup and don’t forget auto-connect

Once you’ve confirmed that a manual connection works, open the client settings and look for “Start on boot” or “Launch at startup.” After enabling it, restart Windows, sign in, and check whether the client is running in the taskbar’s notification area. If its icon isn’t there, check whether it’s disabled under Windows “Settings → Apps → Startup” or on the Startup apps page in Task Manager. Menu names may vary by Windows version.

“Start the client on boot” and “connect automatically at startup” are usually separate settings. If you enable only the first, you may see the client icon after restarting while the route remains disconnected. If the client offers auto-connect, decide whether to enable it and check that it connects to your chosen route or a route the client recommends as available. Restart again after setup, then check separately that the client starts, the route connects, and the exit information is as expected.

Auto-connecting to an international route may not be suitable on a shared computer or in an environment where you need to connect to a local office network first. You can set the client to start on boot without connecting automatically, then connect manually when needed. If subscription updates fail or a route stops working, open the client and check its messages. Starting on boot won’t fix a broken link or determine which route a website needs.

  • ✅ After restarting, you can find the client in the Start menu or notification area.
  • ✅ If you enabled auto-connect, the client shows that the route is connected.
  • ✅ Check your exit information again instead of relying on the startup icon as proof that the connection works.
  • ❌ Don’t treat “start automatically,” “connect automatically,” and “update subscription automatically” as the same setting.

Troubleshooting: check each step in order

When something goes wrong, start with the part closest to the problem. If the client won’t open, check the installation and system messages. If no routes appear, check the subscription link and update status. If a route won’t connect, try another one and read the error message. If the client says it’s connected but websites won’t load, check the system proxy, split tunneling rules, DNS, and browser settings. Don’t reinstall the client, replace the subscription, change the proxy, and edit the rules all at once. Even if that fixes access, you won’t know what caused the problem.

If only one app can’t connect but your browser works, first check whether that app follows the system proxy. If only one domain has a problem, check whether it matches the current split tunneling rules. If the issue started after your local network changed, disconnect and reconnect; restart the client if needed. If you still can’t pinpoint the cause, note the client’s error message, the selected connection mode, and the steps that led to the problem. Then check the protocol and troubleshooting guide one item at a time. Avoid sharing screenshots publicly if they show your subscription link.

Setup order: First verify a manual connection, then configure split tunneling, and finally enable startup. Test after each change so you can tell whether the problem is with the import, route, traffic-capture mode, or startup settings.