v2rayNG Setup Guide 2026: VLESS Reality on Android
Your VPN died mid-scroll and every “how to set up v2rayNG” post stops at the happy path. This one covers the parts that actually break: picking the right config, verifying your IP changed, and what to do when the tunnel connects but nothing loads.
v2rayNG is the most-used Xray client on Android. It is a shell — it runs whatever VLESS, VMess, or Trojan config you feed it. Get the config right and it is bulletproof. Get it wrong and you will stare at a spinning icon. Here is the full path, plus the fixes nobody documents.
If you want the deeper protocol background first, read our Xray VPN for Android guide.
Install v2rayNG (Play Store, APK, or F-Droid)
Three ways to get the app, in order of how current they stay:
- GitHub APK (most current) → the official 2dust releases page ships the newest builds first. Download the
arm64-v8aAPK for modern phones. You will need to allow “install from unknown sources” for your browser once. - Google Play → simplest, but the Play build sometimes lags behind and Play itself is unreliable in Iran and parts of Turkey.
- F-Droid → good if you avoid Google services entirely.
After a manual APK install, open the app once so Android registers the VPN service. On first connect it asks for VPN permission — that is the standard Android prompt, tap OK.
One note for censored regions: if the Play Store or GitHub is throttled when you try to download, grab the client over any working connection first, even a slow mobile-data window. The client rarely changes. The config is the part that expires.
Import a config: clipboard, QR, or subscription URL
v2rayNG takes a config three ways. Each suits a different situation.
Clipboard (single server). Copy a vless:// link. In v2rayNG tap the + in the top-right, choose Import config from Clipboard. The server appears in your list instantly. This is the fastest method for one config.
QR code (phone-to-phone or from a page). Tap + → Scan QR code. Point the camera at the QR. Providers that show a QR next to each server — including Veilora’s free configs page — are built for exactly this. No typing, no paste errors.
Subscription URL (the one you actually want). This is the upgrade most people skip. Open the left drawer → Subscription group setting → + → paste the subscription URL → save. Then tap the three-dot menu → Update subscription. v2rayNG pulls every server on that link at once and re-pulls them whenever you hit update. When a provider rotates IPs or adds a location, one tap refreshes your whole list. Single links go stale silently; a subscription heals itself.
For self-hosters or advanced users, v2rayNG also accepts a manual entry (server, port, UUID, flow, Reality public key and shortId), but if a provider gives you a link or a subscription, use that — hand-typing a UUID is how you spend an hour debugging a typo.
Pick the right config for your network
Importing gives you a list. Choosing well is where reliability lives. A few rules:
- Match the transport to your blocking. A plain VLESS+Reality server over TCP is fast and clean where DPI is moderate — think Turkey or India. Where blocking is aggressive (Iran, UAE), you often need XHTTP or a CDN/WebSocket config that rides Cloudflare, because a CDN can’t be blocked without taking down half the legitimate web with it.
- Pick a nearby location. Closer server = lower latency. From Turkey, European exits (Germany, Bulgaria, Romania) feel best. From Iran, Frankfurt and Amsterdam are common picks. This is about geography, not magic.
- Understand SNI, don’t copy ours. Reality configs carry an SNI — the domain your handshake pretends to visit. A good SNI is a large, high-traffic site reachable from inside your country, ideally CDN-backed, that isn’t itself blocked. That’s the selection criterion. Providers rotate these deliberately, so treat the SNI in a fresh config as correct and don’t hard-swap in a random domain you read somewhere.
If you don’t want to reason about any of this, a managed provider picks the transport, location, and SNI for you and rotates them when they degrade. That’s the whole value of a maintained list over scraped free links.
Connect and verify your IP actually changed
Tap the server, then the round connect button at the bottom. First time, approve the VPN permission. The button turns green and the notification shows a V icon.
Now verify — connecting is not the same as working:
- Open a browser and go to a “what is my IP” page, or
ipleak.net. - The IP and country should match your server’s location, not your ISP.
- On
ipleak.net, scroll to the DNS section. It should show the VPN’s DNS, not your carrier’s. A mismatch here means a DNS leak.
In v2rayNG you can also long-press a config and run Real ping to measure the actual round-trip, or tap the speedometer icon in the config list to test all servers and sort by latency. Use the fastest one that stays connected — sometimes the lowest-ping server isn’t the most stable under DPI.
If the IP still shows your real location, the tunnel isn’t carrying traffic. That’s the next section.
Common fixes: expired config, wrong SNI, throttling
Connects but nothing loads. Ninety percent of the time this is DNS or SNI. In Settings, set a custom DNS such as 1.1.1.1 or 8.8.8.8 — some configs omit DNS and fall back to your (blocked) carrier resolver. If it’s a Reality config, the SNI may not be reachable from your network; try a different server from the list.
Config worked yesterday, dead today. It expired or the IP got blocked. This is normal for free public configs. Re-import a fresh one, or — better — use a subscription URL so Update subscription grabs the current set in one tap. Rotating sources like veilora.net/free-configs exist for this.
Reality handshake times out. Usually a stale shortId or public key, or an SNI your ISP now blocks. Re-download the config from the provider rather than editing fields by hand.
Everything connects but it’s crawling. Your ISP may be throttling the exit or the port. Switch from a direct TCP config to an XHTTP or CDN config — CDN traffic looks like normal Cloudflare and is much harder to throttle selectively. Also try port 443 if you’re on something exotic.
Can’t even install v2rayNG. Use the Veilora Telegram bot — it hands you a working config without the Play Store, and the Veilora app itself needs no manual client at all.
A realistic note: for Iran specifically, no client setting is a silver bullet. Iran is genuinely hard, and even a perfect v2rayNG setup lives or dies on how fresh and well-chosen the config is. Turkey and India are far more forgiving — a solid VLESS+Reality config there tends to just work.
Or skip all of this
Everything above is the manual path. It’s worth knowing, and for self-hosters it’s the only path. But if you just want a connection that stays up, the Veilora Android app is built on the same Xray-core engine and does every step here automatically: it imports the config, picks the location, selects and rotates the SNI, and falls back to CDN when a direct handshake fails. No vless:// links, no QR scanning, no DNS tweaking.
In a May 2026 survey across 60 ISPs in four censored countries, our VLESS+Reality tunnel restored 92-98% of locally blocked sites — Turkey 92%, Pakistan 98%, India 92%, Indonesia 97% (how we test). Same protocol you’d run in v2rayNG, maintained for you.
Next step: grab a fresh config from veilora.net/free-configs and import it with the subscription-URL method above — 10 GB/month free, no sign-up. If you’d rather not touch v2rayNG at all, install the Veilora app and tap connect.
Try Veilora free
10 GB every month, free. No credit card required.
Veilora