Names follow the installed version. The usual three are Config, Proxy, and Direct. Some builds label Config closer to “Rule.” The meaning is the same: follow the enabled conf. The Config tab at the bottom is a different entry. It manages conf files. Do not mix it with this home-screen control.

What each option does

Config sends traffic to proxy or Direct using rules in the current conf. Rules may come with a subscription or from a rule set you update later. Matched domains or IPs use the assigned policy; unmatched traffic uses the default. Daily use should stay here. It depends on complete rules. With nodes but no rules, behavior follows the provider default. Read the provider notes instead of guessing in the app.

Proxy forwards most requests through the selected node. It answers one question: can this destination open when everything goes through the node? If Proxy works and Config fails, rules or DNS likely sent that domain to Direct or the wrong policy group. Use Proxy for a short comparison, not as a long-term default. Local banking, intranet, and some carrier portals often fail when everything is proxied.

Direct skips the node. The tunnel may still show connected, but traffic is not forwarded. Use it to check three things: whether the local network works, whether the site itself is down, and whether the problem is the node rather than the phone. If Direct fails, changing nodes does not help. Check Wi-Fi or cellular, the system clock, and whether the site fails with no VPN at all.

Change only one thing when you compare

If you change the node, routing, and DNS together, you will not know which step fixed it. Keep the same node and the same test address, and watch in this order:

  1. Switch to Direct. If it still fails, the problem is the local network, DNS, or the destination—not the current node.
  2. After Direct works, switch to Proxy. If that fails, change the node, or ask the provider whether the node is restricted or needs UDP.
  3. If Proxy works and Config fails, check rules, policy groups, and DNS. Do not keep changing nodes.

After each switch, confirm the status-bar VPN icon is still there, then open the same address. If the icon is gone, the tunnel dropped. Go back to VPN permission instead of tuning routing. Turning VPN off in Control Center is a disconnect. It is not the same as setting Global Routing to Direct.

How this relates to conf files and rule sets

The Config tab at the bottom lists conf files. When Global Routing is Config, it uses the enabled file. After you import a subscription, some providers put nodes and rules in the same feed; others split them. Updating nodes without updating rules does not refresh routing. Updating rules also does not change the node you selected.

A policy group collects several servers and picks an exit by latency or by hand. The node you tap on Home may not be the exit the group finally uses. If a few sites fail in Config, see which rule that domain hit and which group it entered before you change the home-screen node.

After you edit rules or switch conf files, confirm Global Routing is still the option you think it is. People often leave it on Proxy after a comparison and then believe “rules broke recently.” There is no “Proxy is always faster” or “Config is always faster.” It depends on the destination and the node at that moment.

Read it with DNS and IPv6

If only some domains fail and changing nodes does nothing, suspect DNS or rules before a mistyped server field. After you set a remote DNS, Config and Proxy may resolve on different paths. On a broken IPv6 network, handshake failures sometimes appear in only one routing mode. Locations are on Settings.

A latency-test number cannot replace the comparison above. The test uses a probe address, not the site you are opening. See latency tests.

What not to do at the same time

  • Switching all three options and refreshing the page before you confirm the VPN icon is still there.
  • Treating “Proxy works” as proof the rules are wrong and deleting the whole conf.
  • Using a Direct failure as proof the subscription expired. Direct does not use the subscription.
  • Renaming controls from outdated third-party screenshots. Use the labels on the installed version.

Keep the connectivity test separate from Global Routing. The test checks whether the current tunnel can reach a probe. It does not change routing. Passing a test does not mean Config now sends every site through the proxy. After a pass, still compare the three options to see which path a given domain uses.

Display names in the home server list can be edited. That does not change Global Routing or the conf. Routing is decided by the enabled file and which option you leave selected. On a long list, find the node by the provider’s name first, then change routing, so you do not blame Proxy vs Config for a tap on the wrong node.

Some versions also switch by scene. A scene is a preset and may change the node and routing together. When you use a scene to compare a failure, see where Global Routing lands after the switch, then open the same address. Do not assume “Auto” in the scene name means the rules are already optimal.

On a captive portal (hotel, airport, campus), switch to Direct, finish sign-in, then return routing to Config. If the portal is sent through the proxy, it often fails and looks like a dead node. After sign-in, and after Direct can open a normal site, restore the option you use daily.

Button locations and home screenshots are in the illustrated tutorial. Feature boundaries are on Features. This site does not provide nodes or rule subscriptions. Without a valid configuration, none of the three routing options can create proxied access.