How to use a VPN on Windows: a step-by-step setup guide

Follow five steps: install the client, import your subscription, choose a server, verify the connection, and enable startup. Each step explains what to click and what to look for, so first-time users can get set up with confidence.

To use a VPN on Windows, first get the Windows client and subscription details from your service dashboard. Then install the client, import the subscription, choose a server, verify the connection, and enable startup if needed. The tricky part isn’t clicking “Connect”—it’s making sure the client reads the subscription, your traffic follows the intended route, and your settings still work after a restart. Follow the steps below in order. Labels may vary slightly between client versions, so look for the corresponding features.

Before you start: understand clients, subscriptions, and servers

The client is the program installed on your computer; it displays servers, connects to them, and manages traffic. A subscription is the service’s source for server configurations, usually imported via a link or file. A server is the location and connection method you choose when connecting. These are separate things: if no servers appear after installation, you’ll usually need to import a subscription. Even after a successful import, your computer won’t necessarily be using a server yet—you’ll also need to check the client’s connection status and proxy mode.

Windows’ built-in VPN settings are for cases where the service explicitly provides a compatible system configuration. If you have a subscription link intended for a dedicated client, don’t paste it into the server address field in Windows VPN settings. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different connection protocols. Whether a client can read a particular subscription or connect using a given protocol depends on the client’s documentation and the configurations included in the subscription—not just what the link looks like. Check the client guide in your service dashboard before installing; it’s easier than troubleshooting by trial and error.

What you see What it’s for What to do next
Windows client installer Manage connections and servers on your computer Download and install it using the link in your service dashboard
Subscription link or configuration file Provides server settings to a compatible client Add it under the client’s import or subscription settings
Location, server name, and connection status Choose a server and check whether it connects After choosing a server, verify the route your traffic takes

Install the Windows client: check the source and permissions first

Open the downloads section in your service dashboard and choose the client for Windows. For VPNJH, you can find client information through the dashboard download page; follow the instructions currently shown on the download page. After downloading, check the file name and source, then follow the installer. If Windows asks for permission, make sure you’re running the installer you just downloaded before approving it. Don’t skip checking the file source just to save time.

When you first open the client, look for options such as “Subscription,” “Import,” “Servers,” or “Configuration.” Some clients ask you to choose a configuration format first; others open to an empty server list. An empty list doesn’t necessarily mean installation failed—the program is ready, but it hasn’t received server details yet. If you can’t find the window after installation, check the taskbar notification area. Many Windows networking clients keep running in the system tray after you close their main window.

Import a subscription to populate your server list

In the client, look for “Add subscription,” “Import from URL,” or a similar option, then paste in the subscription link from your service dashboard. If you received a configuration file instead, use the option for importing a file. Confirm and refresh the subscription, then wait for the server list to appear. Client support for subscription formats varies, so the safest approach is to use the client and import method recommended on the service’s download page—not a random app with a similar name.

After importing, check two things: whether the subscription shows a successful update and whether locations appear in the server list. If you see a format error, check for extra spaces or line breaks and make sure you didn’t use your dashboard login URL instead of the subscription link. If the update succeeds but no servers appear, check for active filters, collapsed groups, or a subscription that needs to be retrieved again from the dashboard. If the subscription address has changed, get the new one from your service dashboard instead of repeatedly refreshing the old link.

  1. Open subscription management in the client and choose link import or file import.
  2. Enter the configuration for your client, save it, and refresh the subscription.
  3. Check the update status and server list, then open the connection settings.

Choose a server and mode to control how traffic is routed

For your first connection, choose a server in the region where your target website or service is based, then check the connection status shown in the client. Server names may include terms like direct, relay, or IEPL. A direct route typically connects from your local network straight to the access point; a relay goes through an intermediate node before reaching the destination region. IEPL describes the service’s dedicated-line transport arrangement. These labels describe the route type, not a guaranteed speed or latency. Your experience also depends on your local network, the destination site, and the time of day.

Next, choose a traffic mode. “Global proxy” typically routes more traffic handled by the client through the selected server, making it useful for checking whether a connection works. “Rule-based routing” uses domain, address, or application rules to decide which requests use the server—useful for separating everyday local browsing from international websites. Some clients also offer per-app routing, which is different from routing by website rules. Start with a simple mode to verify the connection, then adjust the rules for your needs. This helps avoid mistaking a rule that didn’t match for a server connection problem.

Also check options such as “System proxy” and “Virtual network adapter.” System proxy affects apps that follow your system proxy settings. Virtual network adapter mode can handle more types of traffic, but may require extra permissions or conflict with other networking tools. This can affect how games, work apps, and browsers behave. Choose the routing method that fits your apps and follow the client’s documentation—don’t rely solely on a “Connected” label.

Verify the connection: check your route and DNS

After clicking Connect, make sure the client shows a connected status. Then open a browser and visit a page that displays your public IP address and its location. Compare the results before and after connecting to see whether the exit location matches your selected server. Location lookups rely on third-party databases and can occasionally be inaccurate. If the page loads and your public IP has changed, consider that alongside the client status and how your apps behave; don’t draw conclusions from a location label alone.

DNS translates website names into addresses. Even if your browser traffic goes through the selected server, DNS queries don’t necessarily take the same route. To check for DNS leaks, use a trusted DNS test page and review the resolver it reports alongside your client’s DNS settings, routing rules, and current network environment. Before testing, turn off other networking tools that could change the DNS route, so you don’t attribute the combined results to the current client. Your browser’s Secure DNS setting may also affect the results.

Finally, test the website or app you actually plan to use instead of relying only on the client’s connection icon. If a site works in your browser but not in a desktop app, check whether the app follows the system proxy and whether the client is configured to handle that app’s traffic. Local websites using your regular connection may simply be following your routing rules as intended.

  • ✅ The client shows a connected status, and the selected server matches your target region.
  • ✅ The public IP lookup and actual website behavior match the current proxy mode.
  • ✅ DNS test results have been checked against browser settings and client rules.
  • ✅ Common desktop apps have been tested individually, not just the browser.

Enable startup: check the connection again after restarting

Once you’ve verified the connection, decide whether to enable “Start on boot” in the client settings. This usually means the program launches when you sign in to Windows; it doesn’t necessarily select a server or connect automatically. If you want it to reconnect on startup, check whether the client has a separate “Auto-connect” or “Restore previous state” setting. Enable these options based on how you use your computer. If you need to connect to a work network first, pay attention to the startup order.

Save your settings and restart your computer. Look for the client icon in the taskbar notification area, open the main window, and check the subscription, server, and connection status. Then revisit a site you commonly use. If the app launches but doesn’t connect, don’t reinstall it right away. First check whether auto-connect is enabled, whether the previous server is still in your subscription, and whether Windows allows the client to run at startup. If multiple networking tools start routing traffic after a restart, pause the others first, then re-enable them one by one to identify any conflicts.

Troubleshooting connection problems

“No servers listed” and “servers listed but none connect” are different problems. For the first, check subscription management, the import method, update status, and filters. For the second, try another server suited to your target region and check that your local network is working. If the client says it’s connected but your browser isn’t behaving as expected, check the proxy mode, the browser’s own proxy or DNS settings, and whether another program has changed the system proxy.

If just one app can’t connect, first check whether it needs the system proxy, per-app routing, or virtual network adapter mode. Don’t change all your rules without understanding the impact just to get one program working. If the connection keeps dropping, note the server name, client error, and any changes to your local network, then look for relevant guidance on the Help page. Clear details make it easier to diagnose the issue than simply saying “it doesn’t work.”

In short: First make sure the client has loaded your subscription, then choose a server and connect. Verify the connection using your public IP and the apps you use, then test startup behavior. If something goes wrong, check the server list, connection status, traffic mode, and specific app—in that order. This is more useful than reinstalling repeatedly.

Once you’ve completed these checks, everyday VPN use on Windows comes down to a few choices: where you want to connect, which apps should use the server, and when to connect automatically. Keep your settings easy to understand, and it’ll be simpler to pick up where you left off the next time you turn on your computer.

Start Free