Setting up a VPN on Android isn’t just a matter of tapping “Connect” over and over. The client, subscription, system permissions, and background access all need to work together. Menu names vary by Android version and manufacturer, but the steps are largely the same: check that the client supports your subscription, import the configuration, allow Android to establish the VPN connection, then verify your exit IP. Follow the steps below in order. If a button has a different name on your device, look for an option with the same function.
Before installing: check client and subscription compatibility
Start at the VPNPH client download page to review the Android installation instructions and recommended client, then install the app as directed. Don’t choose an app just because its name sounds similar: what matters is whether it can read the node types in your subscription and supports the required traffic-routing options. Once installed, open the app and check for an option to import a configuration or add a subscription.
A subscription link isn’t a regular webpage URL; it lets the client retrieve your connection configuration. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different protocols or configuration types. Don’t manually enter one protocol’s settings into a form for another. Whether a configuration will work depends on the subscription contents and the selected client’s actual capabilities. If the download page recommends a specific client, follow its instructions rather than guessing which protocol to use.
Also check that your phone has a working internet connection before you begin. Disconnect the client, then use a browser to open a site you can normally access. If the underlying connection isn’t working, seeing “Connected” later won’t tell you whether the issue is with the subscription or the network.
Import the subscription: load your nodes into the client
Sign in to the service dashboard and find the subscription link for the Android client. Copy it as instructed on the page. In the client, open “Configuration,” “Subscription,” or “Add,” choose the option to import from a link, paste the URL, save it, and update the subscription. Some apps separate saving from updating. If the list is still empty after saving, look for a refresh or update button.
- Copy the subscription link for your selected client from the dashboard. Don’t add extra spaces or line breaks.
- In the client, choose “Import from URL” or a similarly named option under Add Configuration, then paste and save the link.
- Update the subscription and wait for the node list to load. If the client asks you to select a configuration file, switch to the one you just imported.
- Choose a node suited to what you want to access. Keep the default routing settings for now and verify the connection first.
If the client says the format isn’t supported, make sure you copied the subscription link rather than the dashboard URL, then check that you’re using a client recommended in the download instructions. If the import succeeds but the list is empty, update it manually and check whether your current network can reach the subscription URL. Don’t change protocols, ports, or encryption settings at random; use the values from the actual configuration.
Connect: allow Android to establish the VPN
Select a node from the list, then tap the client’s connect toggle. The first time you connect, Android will usually show a VPN connection request. Check that the app name matches the client you just installed, then tap “OK” or “Allow” in the system dialog. This grants system-level permission; it isn’t a request to buy the service again in the client. If you deny permission, the client may keep the selected node but won’t be able to connect. Tap Connect again and approve the system prompt.
After granting permission, check the connection in the status bar or under VPN in Settings. Status icons and menu paths vary by manufacturer, so don’t rely on the icon alone. Consider all three: the client reports a connection, Android shows the VPN as enabled, and your exit IP changes as expected. If another app is using Android’s VPN interface, such as a different VPN client or a local filtering tool, pause it and try connecting again.
Allow background activity to prevent disconnects when the screen locks
If the VPN connects but often disconnects when the screen locks, check how the system manages the client in the background. Long-press the app icon, open “App info,” and look for “Battery,” “Battery usage,” or “Background activity.” Allow the app to run in the background, or select “Unrestricted” if available. Some phones also have “Auto-start” or “Sleeping apps” settings; remove the client from any sleep list. Return to the client, reconnect, then check the connection after locking and unlocking the screen.
These settings change background permissions for the client app; they don’t disable battery management for every app. If your phone separates work and personal profiles, check which profile has the client installed and which profile contains the apps that need network access. Their network policies may differ. After a system update, check the battery settings again if the VPN starts disconnecting when the screen locks, as the manufacturer may have reset the app’s background settings.
Check routing and DNS: a successful connection doesn’t guarantee traffic is using the right route
For your first test, keep the client’s default rules and avoid adding custom ones. Common modes include Global, Rule-based, and Direct. Global mode is useful for a quick check to see whether routing rules are affecting a specific destination. For everyday use, choose which traffic should use international routes and which should connect directly based on what you’re accessing. Rule-based routing may match domains, IP addresses, or apps; the priority depends on the client’s configuration, so the mode name alone doesn’t reveal where all traffic goes.
| What you see | Check first | Next step |
|---|---|---|
| Connected, but the site still uses the original network | Whether a routing rule sends the destination directly | Temporarily switch to Global mode for comparison, then adjust the rules |
| A website won’t open, but other apps work | DNS resolution and the app’s routing settings | Try another node and check the client’s error message |
| Reconnect after unlocking the screen | Battery restrictions and background activity permissions | Allow background activity, then check again |
| Subscription update failed | The link, client type, and current internet connection | Copy the link again and import it using the download instructions |
Check DNS alongside your routing rules. If domain lookups are handled by an unexpected network, the site may resolve incorrectly, or DNS queries may take a different route from web traffic. Review the client’s DNS settings and documentation, then use a trusted test page to check the results. A slow-loading site alone doesn’t prove there’s a DNS leak. If Android Private DNS or another filtering app is enabled, check whether its settings conflict with the client.
Verify your exit IP before changing nodes
Keep the client connected and open VPNPH’s My IP page to check your current exit IP against the result with the VPN disconnected. With rule-based routing, whether the test page uses the VPN depends on which rule it matches. If the result hasn’t changed, check the rules before assuming the connection failed. You can also open a site you need to access and see whether it loads reliably, then check the client for any specific connection errors.
Choose a node based on how you’ll use it. IEPL, relay, and direct connections describe different network paths. Dedicated and relay routes typically involve additional routing arrangements, while direct connections depend more on the path from your local network to the destination. The name alone can’t replace a real-world test. If video loads slowly or a collaboration app disconnects, keep your routing and app settings the same while testing available nodes to determine whether the issue is the route or the configuration. Don’t treat a single test as a guarantee of long-term speeds.
- ✅ After updating the subscription, the client shows available nodes.
- ✅ Android has allowed the client to establish a VPN connection, and the client isn’t showing persistent errors.
- ✅ The destination is accessible, and the exit IP check matches your routing rules.
- ✅ After locking and reopening the screen, the connection behaves as expected.
- ❌ If the list is empty, permission is denied, or only one app has a problem, troubleshoot that specific step instead of reinstalling every configuration.
Still not working? Troubleshoot one step at a time
Separate the problem into categories: “can’t import,” “can’t connect,” “connected but can’t access anything,” or “disconnects when the screen locks.” This is usually more effective than switching nodes repeatedly. If you can’t import, check the link and client. If you can’t connect, check system permissions, your internet connection, and whether another VPN app is using the interface. If you’re connected but can’t access something, check routing, DNS, and the target app. For screen-lock disconnects, revisit the battery settings. Change one setting at a time and repeat the same test so you can identify what helped.
If you contact support, include your Android version, client name, selected mode, error message, and steps to reproduce the issue. Before sharing a screenshot, hide your subscription link, configuration credentials, and any addresses you don’t want to share. To check node and plan details, see the node list and plans. Compare the node names on the page with the configurations in your client.