v2rayNG Android Setup Essentials: VpnService Permission, Battery Optimization and Per-App Proxy Settings

Learn how to grant VpnService permission, exclude v2rayNG from battery optimization, and configure per-app proxying on Android to prevent disconnects and route only the apps you choose.

At a glance

This guide is for v2rayNG users who have imported a subscription but are unsure about the first permission prompt, lose connectivity after locking the screen, or want to proxy only selected apps. By the end, you will know how to grant VpnService permission, adjust battery restrictions, configure per-app proxying, and use logs and connection status to diagnose common problems.

Check the prerequisites before connecting

v2rayNG is a graphical Android client that commonly uses the Xray core to process VLESS, VMess and other configurations. After importing a subscription, the app passes node parameters to the core, which creates a local virtual network interface through Android's VpnService. Here, “VPN” refers to the system traffic-capture mechanism; it does not fill in a server address, user identifier, TLS domain or Reality parameters for you. Those details must still come from a valid subscription or a complete manual configuration.

Before you begin, check that the system time is set to sync automatically. TLS connections rely on an accurate clock; a large time offset can cause errors such as a certificate not yet being valid, an expired certificate or a failed handshake. Open system “Settings” → “System” → “Date & time” and enable automatic date and time and automatic time zone. Menu names vary by device, so you can also search for “Date & time” in system settings.

Android 8+
Recommended environment
10808
Common local SOCKS port
1
Active VpnService at a time
1500
Common default MTU

Local ports and MTU values may vary by version, configuration template or user changes. Treat these numbers as troubleshooting references, not settings to copy blindly. If you changed a parameter before, check the local SOCKS port in v2rayNG “Settings”. If the network connects but some pages keep loading, test an MTU of 1500, 1400 or 1280; change only one value at a time and reconnect after each test.

Grant VpnService permission for the first connection

When you tap the connect button on the v2rayNG main screen, Android displays a system-level connection request. This dialog is provided by Android; v2rayNG cannot create the virtual network interface or capture device traffic until you confirm it. The prompt usually appears only on the first connection, after app data is cleared, or after the system revokes permission.

Android normally allows only one active VpnService at a time. If another network tool is already connected, starting v2rayNG may disconnect it; starting another tool later may replace v2rayNG in turn. A key-shaped or VPN indicator in the status bar only confirms that the system interface exists—it does not prove that the remote node is working.

  1. Select a node

    Tap the target node in the v2rayNG configuration list. Use the top-right menu to run “Test all configurations for real connection” or run a latency test for the target node first. A latency result only shows whether the test request returned; you still need to verify an actual connection.

  2. Start the connection

    Return to the main screen and tap the circular connect button at the bottom. On the first use, wait for Android to show the VpnService connection request instead of tapping repeatedly.

  3. Confirm permission

    Confirm the connection in the system dialog. If the device uses a work profile, parental controls or enterprise management policies, the permission screen may be restricted by administrator rules.

  4. Check the status

    Make sure the main screen changes to Connected, then open a familiar website to test it. If the status quickly returns to Disconnected, open “Menu” → “Logs” immediately.

  5. Trigger the prompt again

    If the dialog does not appear, disconnect other VpnService instances first. Then open system “Settings” → “Apps” → “v2rayNG”, tap Force stop, reopen the app and connect again.

Exclude v2rayNG from battery optimization to reduce lock-screen disconnects

Many devices restrict background activity after the screen has been off for a while. Although v2rayNG can show a foreground-service notification, it may still be affected by battery optimization, background-start restrictions, sleeping-app lists or data-saver mode. A typical symptom is normal operation while the screen is on, followed by delayed messages after 5 to 20 minutes of screen-off time; reopening v2rayNG then restores the connection.

Prefer the system's per-app battery settings instead of disabling power saving for the entire device. Open system “Settings” → “Apps” → “v2rayNG” → “Battery” and choose “Unrestricted”, “Not optimized” or an equivalent option. If that entry is unavailable, search system settings for “Battery optimization”, switch to all apps and find v2rayNG.

App battery policy

Menu path
Settings → Apps → v2rayNG → Battery
Recommended option
Unrestricted or not optimized
Test duration
15 minutes with the screen locked
What to observe
Whether the connection and messages continue

Names differ across systems; the goal is to allow the foreground service and necessary background network activity.

Background activity permission

Menu path
Settings → Apps → v2rayNG
Background activity
Allow
Auto-start
Enable if required by the system
Recent apps
Avoid one-tap cleanup

Some devices split background activity, auto-start and battery policy into three separate switches. Check each one individually.

Data Saver mode

Menu path
Settings → Network → Data usage
Background data
Allow
Unrestricted data
Enable as needed
Test networks
Mobile data and Wi-Fi

If disconnects occur only on mobile data, focus on background data and unrestricted-data permissions.

Foreground notification

Menu path
Settings → Notifications → v2rayNG
Service notification
Allow notifications
Status check
Remains visible while connected
Warning sign
The notification disappears and the service stops

The service notification shows runtime status. On some systems, disabling notification permission can also affect foreground-service stability.

After making changes, do not stop at a one-minute test. Connect to a node, turn off the screen for 15 minutes, then use both Wi-Fi and mobile data to receive messages and open websites. If the connection breaks only when switching from Wi-Fi to mobile data, wait 5 to 10 seconds to see whether it recovers automatically. If it does not, disconnect and reconnect, then check the logs for timeouts, DNS failures or unreachable-network errors.

Configure per-app proxying for your needs

Per-app proxying determines which app traffic enters v2rayNG's virtual network. It is useful when you want only a browser, messenger or specific work app to use the current node while banking, local-network management or network-location-sensitive apps stay direct. This feature controls the app scope; it is not the same layer as routing by domain, IP address or port.

The usual v2rayNG path is “Settings” → “VPN Settings” → “Per-app proxy”. Some versions show “Per-app proxy” directly in the side menu. Enable the feature first, then choose a proxy mode. If the wording changes after an update, search the settings page for “Apps” or “VPN”.

  1. Open Settings

    Open v2rayNG and go to “Settings” → “VPN Settings” → “Per-app proxy”. If the side menu already has the same entry, open it directly.

  2. Enable the feature

    Turn on “Per-app proxy”. Before enabling it, note the current node and routing mode so you can restore the original configuration if anything changes.

  3. Choose a mode

    Choose “Proxy only selected apps” or “Bypass selected apps” as needed. The first suits a small number of apps that need the proxy; the second suits setups where most apps use the proxy and only a few stay direct.

  4. Select apps

    Choose the target apps from the app list. System component names can be difficult to identify, so for a first setup select only user apps you clearly recognize.

  5. Rebuild the connection

    Save the settings, return to the main screen, disconnect and reconnect so the new app scope takes effect in the current VpnService session.

  6. Verify apps individually

    Open one selected app and one unselected app separately, then check whether websites, sign-in flows and local-network access behave as expected.

“Proxy only selected apps” gives you tighter scope control, but newly installed apps are not added automatically. “Bypass selected apps” requires less maintenance, but you must watch system components and shared network services. Some apps use a system web component, download manager or external browser to complete sign-in. If those helper components do not follow the same policy, the sign-in page may not open, downloads may not start, or the network path may change after a redirect.

Use case Recommended mode What to check
Proxy only two or three specific apps Proxy only selected apps Newly installed apps must be added manually
Most apps should use the current node Bypass selected apps Add local-network and sensitive apps to the bypass list
An app opens an external browser Keep both policies consistent Sign-in callbacks and verification-code pages
Need to access a router admin page Combine routing rules with a direct local-network route Common private address ranges and local DNS

Troubleshoot subscriptions, routing and DNS by layer

A node connecting does not mean every domain will resolve correctly. The v2rayNG path includes at least the subscription configuration, Xray core, DNS queries, routing rules and Android VpnService. Troubleshooting layer by layer is more effective than constantly switching nodes.

The subscription provides the server address, port, user identifier, transport method and security-layer parameters. Common VLESS + Reality fields include serverName, publicKey, shortId, fingerprint and flow; common VMess + WebSocket + TLS fields include the hostname, path, TLS settings and user identifier. These are usually filled in automatically after importing a subscription, but any missing key field can cause a handshake failure.

VLESS + Reality

Transport
TCP
Flow
xtls-rprx-vision
Fingerprint
chrome
Key fields
publicKey and shortId

Use the complete configuration supplied by the subscription. Do not guess security-layer fields from a node name.

VMess + WS + TLS

Transport
WebSocket
Path
Provided by the subscription
TLS
Enable according to the configuration
Key fields
Host and SNI

A path, Host or SNI mismatch commonly causes connection timeouts or TLS handshake failures.

Routing rules determine whether traffic goes through the proxy, connects directly or is blocked after matching. Per-app proxying first limits the app scope; routing rules then process the domains and IP traffic generated by those apps. When you need to access a printer, router or home storage device, keep local-network addresses on a direct route. Common private ranges include 192.168.0.0/16, 10.0.0.0/8 and 172.16.0.0/12.

DNS failures often appear as websites that do not open while direct requests to some IP addresses still get a response. For troubleshooting, restore v2rayNG's default DNS settings and reconnect, then check the logs for resolution timeouts. If the problem occurs only on a particular Wi-Fi network, compare it with mobile data. If both networks fail, inspect the node configuration, subscription update and DNS rules more closely.

Quick fixes for common problems

During troubleshooting, record which network was used, which app was affected, how long the screen was locked, whether the network changed and what the logs reported. This is far more useful than simply saying “it won't connect”. The following cases cover the permission, background-restriction and app-scope problems most often seen during initial setup.

No permission dialog after tapping Connect?

Disconnect any other active VpnService first, then open system “Settings” → “Apps” → “v2rayNG” and tap Force stop. Reopen v2rayNG and tap the connect button once. If the device is controlled by a work profile or management policy, confirm that the administrator allows VPN connections.

Disconnected after ten minutes of screen-off time?

Open system “Settings” → “Apps” → “v2rayNG” → “Battery”, select “Unrestricted” or “Not optimized”, and allow background data and service notifications. Lock the screen for 15 minutes and test again; do not clear v2rayNG from recent apps.

Connected, but websites will not open?

Switch to a node already confirmed to work, update the subscription and restore the default DNS settings. Then check “Menu” → “Logs” for resolution timeouts, connection timeouts or TLS handshake messages. If only one app is affected, check whether per-app proxying excludes it.

Still connecting directly after selecting an app?

Confirm that the mode is “Proxy only selected apps”, save the settings, disconnect and reconnect. If the app uses an external browser or system download component, include the related component in the same policy and test the main app and redirected page separately.

Cannot recover after switching Wi-Fi?

Wait 5 to 10 seconds for the system to complete the network transition. If there is still no connection, disconnect and reconnect manually. If the issue repeats, test Wi-Fi and mobile data separately, then check battery restrictions, background data, Private DNS and MTU—changing only one item at a time.

After setup, keep a simple, reproducible baseline: a valid subscription, one stable node, default DNS, default routing and per-app proxying disabled. Once the baseline connection works, add battery policies, app scope and custom routing step by step. If a later change causes a conflict, you can quickly return to a known working state.

Download v2rayN