v2rayNG Per-App Proxy: A Step-by-Step Android Setup Guide

What per-app proxy means in v2rayNG

Per-app proxy lets you decide which Android applications use the active v2rayNG connection and which applications connect directly. Instead of treating every application on the phone the same way, you create a simple routing boundary: selected apps go through the VPN tunnel, while excluded apps continue to use the normal network path. This is useful when only a browser, messaging app, or work tool needs the proxy, while banking, payment, streaming, or local-network applications should remain direct.

v2rayNG applies this feature through Android’s VPN service. The application does not normally change the Wi-Fi router or configure a traditional Android system-proxy field. After you start the connection and approve the VPN permission, Android sends traffic into the client, and v2rayNG applies its selected app-routing rule. That is why Android may display a VPN key or status notification even when only one or two applications are included.

The exact wording of menu items can vary slightly between v2rayNG releases and Android versions. Look for settings such as per-app proxy, app routing, proxy apps, or bypass apps. The important point is not the label itself, but the rule mode behind it. Before changing anything, confirm that you have a working node and can connect normally. A per-app list cannot repair an invalid subscription, an unreachable server, or a node that fails for every application.

Choose the right app-routing mode

Most v2rayNG builds provide two practical ways to define the app list. One mode proxies only the applications you select. The other mode proxies all applications except those you select. Different versions may describe these modes as a whitelist and a blacklist, or as “proxy selected apps” and “bypass selected apps.” Read the explanation shown in your version before saving the setting, because selecting the correct applications in the wrong mode produces the opposite result.

Proxy selected apps is usually the safest starting point. Add only the applications that need the connection, such as a browser or a particular messaging client. Everything else remains outside the tunnel. This mode reduces unexpected traffic, makes testing easier, and avoids sending sensitive local applications through a remote server by accident. It is a good choice when you have a clear, short list of target applications.

Proxy all apps except selected apps is more convenient when most of the phone should use the proxy. You can exclude local banking, payment, smart-home, or corporate applications that should connect directly. However, this mode has broader coverage and can consume more battery or data. New applications installed later may automatically follow the proxy rule, so review the behavior whenever you add an app that handles sensitive accounts or large downloads.

Do not confuse app selection with domain routing. The app list answers “which application is allowed into the VPN path?” Domain rules answer “which destinations should use the proxy or go direct?” An application may be selected but still access a particular destination directly if routing rules, DNS behavior, or server-side policies say so. Conversely, an unselected application normally cannot be forced through the v2rayNG tunnel merely by editing a domain rule.

  • Use proxy-selected mode when only a few applications need access through the node.
  • Use bypass-selected mode when nearly every application should use the proxy and only a small number must remain direct.
  • Use a narrow list first when diagnosing a connection, then expand it after the initial test succeeds.
  • Review both the app mode and the selected names before assuming the node or core is broken.

Prepare your phone before editing the list

Start by updating v2rayNG from a trusted source and opening the client once. Import a subscription or a single node, then select one node and connect without changing per-app settings. Open a normal web page in the browser and confirm that the connection works. This baseline matters because it separates two problems that look similar: “the selected app is not following the rule” and “the client cannot connect at all.” If the baseline fails, solve that first through the node, subscription, permission, or network path.

Next, close other VPN or proxy applications. Android generally allows only one active VPN service at a time, and security, DNS, ad-blocking, firewall, or corporate-management tools can compete with v2rayNG. Disable those tools temporarily during setup. You can restore them later, but testing with several network controllers active makes the result difficult to interpret.

Keep the phone’s date, time, and time zone correct. TLS-based connections can fail when the clock is significantly wrong. Also check whether Android has restricted v2rayNG’s background activity. A connection that works for one minute and stops after the screen is locked is often a battery-management issue rather than an app-routing issue.

For the first test, choose two easy-to-identify applications: one that should use v2rayNG and one that should remain direct. Avoid starting with a large game, a cloud backup tool, or an application that opens many background connections. A browser is easier to test because you can load a page on demand and compare behavior immediately.

Configure v2rayNG step by step

  1. Open v2rayNG and confirm that the intended node is selected. If the node list is empty, update the subscription or import a share link before continuing.
  2. Tap the main connection control and wait for Android to display the VPN permission request. Approve the request for v2rayNG. If Android asks whether to trust the VPN connection, confirm only when you intentionally want this client to handle the selected traffic.
  3. Open v2rayNG’s settings and locate the app-routing or per-app proxy section. On some releases, the option is under a general VPN, routing, or application settings group.
  4. Choose whether the list means “proxy selected apps” or “bypass selected apps.” Do not proceed until the mode description matches your goal.
  5. Open the application list and wait for installed applications to load. Select the target apps by their visible names. If you use proxy-selected mode, select the apps that must use v2rayNG. If you use bypass-selected mode, select the apps that must stay direct.
  6. Save or leave the settings page according to your version’s behavior. Some builds apply the list immediately; others require you to restart the VPN connection.
  7. Stop the current connection and start it again. Reconnecting is a useful way to ensure Android receives the new VPN configuration rather than continuing with an older session.
  8. Test the selected application first. Load a new page, refresh a feed, or perform another visible network action. Then test the unselected or bypassed application separately.
  9. Return to the app list and make one small change if the result is wrong. Change only one variable at a time so you know whether the problem came from the selected package, the routing mode, or the connection itself.

When the list contains multiple variants of the same service, check the package name indirectly through Android’s app information page. A browser may have a stable name, but a work profile, cloned application, beta build, or manufacturer version can appear as a separate entry. Selecting one copy does not necessarily select another copy with a different package identifier.

Verify routing instead of guessing

A successful VPN notification only proves that Android accepted a VPN interface. It does not prove that every desired application is using the node. Verification should be performed per application. First connect v2rayNG with a deliberately small list. Open the selected app and perform a fresh request. Then stop v2rayNG or switch the app mode temporarily and repeat the same request. A clear difference is more useful than checking the VPN icon alone.

Use the client’s traffic counters, connection logs, or recent request information when available. If the selected app is actively generating traffic but v2rayNG shows no corresponding activity, it may not be entering the VPN path. If traffic appears in the log but the application still fails, the rule is probably working and the remaining issue may involve DNS, the remote node, TLS, or the application’s own connection method.

Remember that some applications open background connections before you begin testing. Close the app from the recent-apps screen, reconnect v2rayNG, and open the app again. This creates a cleaner test. Notifications, widgets, synchronization services, and embedded browsers can also use separate processes. Their traffic may not behave exactly like the main screen of the application.

Do not use only one website as proof. A page may be cached, reachable directly, or blocked by the remote node for reasons unrelated to per-app routing. Test several ordinary destinations, and compare the selected application with a known direct application. If privacy or location matters, use a service you trust and interpret its result carefully; IP checks alone do not reveal every DNS or application-level behavior.

Common problems and practical fixes

The selected app still connects directly. First check whether you accidentally chose bypass-selected mode. Then confirm that the exact application entry is selected, reconnect the VPN, and fully restart the app. If the app uses a work profile or cloned installation, select that separate entry as well. Finally, check whether the app has its own proxy, secure DNS, or network setting that changes its behavior.

Every app uses the proxy. The list is probably in bypass mode with no exclusions, or the current version interprets the setting differently than expected. Switch to proxy-selected mode and select one test app. Reconnect, then verify that another simple app remains direct. This controlled test is faster than adding many exclusions without knowing which mode is active.

The selected app has no network access. Confirm that the node works without per-app filtering. If it does, check DNS mode, routing rules, and the application’s transport requirements. Some services use IPv6, UDP, QUIC, or certificate-pinned connections. A node may handle ordinary browser traffic but fail for a particular application. Try another node before changing many settings, and keep a record of the original configuration.

The VPN disconnects when the screen turns off. Open Android battery settings for v2rayNG and allow background activity or unrestricted battery use where the system provides that option. Disable aggressive battery optimization, task-killer, or memory-cleaning features for the client. Some phone manufacturers place these controls under startup management or background launch permissions. Also keep the persistent VPN notification enabled if your Android version uses it to keep the service visible.

Local devices stop working. A broad proxy-all-except mode can affect applications that discover printers, televisions, NAS devices, or smart-home equipment on the local network. Try proxy-selected mode, exclude local services through the client’s routing options if available, or remove the local application from the proxy path. Be careful with network changes on public Wi-Fi: local access may be restricted by the network itself.

Battery or data usage increases. Reduce the number of proxied applications, avoid proxying backup and video applications unnecessarily, and inspect background synchronization. A VPN service adds some processing overhead, while the remote route can also change how quickly large transfers consume data. If the phone becomes warm, stop background-heavy apps first and compare with a narrow app list rather than immediately reinstalling v2rayNG.

Understand DNS, UDP, and Android limitations

Per-app selection is not a complete privacy guarantee. DNS requests may follow the client’s configured DNS path, the application may use encrypted DNS internally, or Android may handle a system service outside the way you expect. If your goal is to keep a particular application entirely direct, verify its behavior with the client documentation and your Android version instead of assuming that one checkbox controls every related service.

Some applications use UDP or QUIC, while a node or routing configuration may be optimized mainly for TCP traffic. A browser page loading successfully does not prove that a game, voice client, or video call will work through the same node. If only one category of application fails, compare protocol requirements and try a compatible node. Avoid changing app routing, DNS, transport, and core settings all at once; the resulting configuration becomes difficult to diagnose.

Android also has platform restrictions around VPN services, always-on VPN, lockdown mode, work profiles, and device-management policies. A managed phone may prevent users from changing VPN settings or may force traffic through another service. If v2rayNG cannot obtain permission, the VPN switch immediately turns off, or the app list has no effect on a corporate device, check the device policy before treating it as a client defect.

Keep the configuration reliable

After the first successful setup, keep the configuration simple. Record which mode you chose and which apps you selected. This small note is valuable after an update or when helping another person, because “the list looks right” is not enough if the list meaning has changed. Review the list when you install a cloned app, move to a work profile, or replace a browser.

Update subscriptions only from the provider’s real subscription address, and do not replace a working node merely because one application fails. Test the current node in ordinary browsing first, then test the target app. When upgrading v2rayNG, export or otherwise preserve important settings if your workflow supports it, and verify the app-routing mode after the update. A version change can reset permissions or expose new routing options.

For everyday use, start v2rayNG before opening the applications that need the proxy. If an application cached a failed connection, force-close and reopen it after the VPN is active. When you no longer need the proxy, disconnect it rather than leaving a broad bypass-mode configuration running all day. This makes the phone’s network state easier to understand and reduces accidental traffic through the remote server.

Frequently asked questions

Does per-app proxy require root access? No. v2rayNG normally uses Android’s user-approved VPN service, so standard devices can use app routing without root. The phone may show a VPN notification, and only one VPN service can usually be active at a time.

Why does selecting an app not affect its notifications? Notifications may come from a separate background process, a system service, or a different app entry. Recheck the selected package, reconnect the VPN, and test the app while it is open. If the main traffic works but notifications do not, the notification service may follow a different path.

Should I proxy all apps for better results? Not automatically. Proxying all apps can help when many services require the same route, but it increases traffic, battery use, and the chance of affecting local or sensitive applications. Start with proxy-selected mode and expand only when testing shows that more coverage is necessary.

Is v2rayNG broken if one app still fails? Usually not. Confirm that the node works in a browser, verify the app mode and package selection, then inspect DNS, UDP, QUIC, and the application’s own network behavior. One failing app often indicates compatibility or routing details rather than a completely failed client.