Settings

This page follows the groups on the Settings tab. It explains what each item changes, and when you should touch it. Nodes, subscriptions, and rules are not here. Names follow the installed version. Screenshots may be Traditional Chinese; the English layout matches—find items by position.

Before you change settings, confirm Home can connect by hand and the status bar shows VPN. Change one item at a time and write down the old value. If you cannot connect, check the node, the subscription, and VPN permission first. Do not start by trying every setting here. Steps are in the illustrated tutorial.

Language

A group of its own at the top of Settings. Match the first row in the screenshot on the right.

Language

Changes menu copy only, not connection parameters

You can switch among English, Chinese, and other supported languages. You do not need to buy again or re-import subscriptions. Node addresses, ports, rules, and subscription URLs stay the same.

Official screenshots on this site come from the Hong Kong storefront and use Traditional Chinese. On English iOS, find the same rows by position: 未連線 is Not Connected, 全域性路由 is Global Routing, 伺服器節點 is Server, 按需求連線 is On Demand, and 設定 is Settings.

Advanced

The Advanced group in the screenshot: latency test, Today widget, On Demand, Diagnostics, and Color. The last two open another screen. Those screenshots sit next to the matching section.

Latency test method

Usually TCP by default · used by the connectivity test on Home

It decides how the connectivity test samples. It is not the connection switch, and it does not choose which node carries traffic. The milliseconds or “timeout” are one sample. They depend on Wi-Fi / cellular at that moment, node load, and the probe target.

  • The first connection does not need the lowest latency. A node the provider marks as usable is enough.
  • If everything shows timeout: update the subscription in Config first, then change a node. Do not change the test method first.
  • If one row is much higher and the others look normal: that node is usually down at that moment. Change the node. Do not change the global test method.
  • Change the method only when “the same nodes, the same network, but the numbers look wrong.” After you change it, test the same node again.
  • Do not change this while you also change the node, DNS, or Global Routing, or you will not know which change mattered.

Today widget

A shortcut switch in Notification Center / Today view

The widget and the master switch on the first row of Home control the same system VPN, not a second tunnel. On in one place and off in the other is still a connect or disconnect. It is easy to read as a “broken switch.”

  • For daily use, operate in one place: Home or the widget.
  • If you turn VPN off in Control Center, the app shows Not Connected when you return. Turn it on again.
  • If the widget does nothing: confirm the Shadowrocket VPN configuration is still in the system, and that another VPN app has not taken over.
  • iOS limits widget refresh. Status can lag. Trust whether VPN appears in the status bar.

Color

Changes UI colors only

It does not change nodes, rules, latency, or battery use. You do not need to reinstall or update a subscription. It is the last thing to try when troubleshooting. Rule out permission, nodes, and routing first. Do not start by changing the color.

Settings home
Settings home. The image stays beside the text as you read the left column.

On Demand

A separate page opened from Settings → Advanced.

Automatic on/off by network or domain

Turn this on only after a manual connection already works

Use it when a manual connection is already stable and you want fewer switch flips. Leave it off while you are still troubleshooting. Automatic connect and disconnect makes the cause hard to see.

Master switch. The rules below apply only after it is on. Off returns you to fully manual.

Network. Which interfaces the rules apply to, usually Any, Wi-Fi, or Cellular. Use this when only one network fails: for example cellular works and office Wi-Fi fails. Then see whether that Wi-Fi blocks VPN. Do not reinstall the app first.

Disconnect on sleep. Drops the tunnel after the device sleeps to reduce background use. After you turn it on, you may need to reconnect when you unlock. It is usually off by default. If battery use or heat is high and VPN stays up for a long time, try it for a day.

Show disconnect messages. Separates “a rule disconnected on purpose” from an unexpected drop. Leave it off for daily use to avoid notification noise. Turn it on when you are tracing repeated drops.

Add domain / On Demand rules. Matching hostnames apply the matching rule. *.google.com in the official screenshot is only an example. Do not copy it. Add only domains you actually need to handle automatically. If rules and system status disagree, trust whether VPN is in the status bar.

On Demand
On Demand page

Diagnostics

Opened from Settings → Advanced. Keep logs off for daily use.

Logs and system comparison

Turn on only while troubleshooting · turn off when you finish

Logs increase battery use and disk writes. Match the items on the right.

  • Enable logging: the master gate. If it is off, later log pages have no new content.
  • Rotate frequency: related to log rotation. Do not change it if you do not know what it does, or older records may not match the failure you are looking at.
  • VPN log: when the tunnel came up and when it dropped. Lined up with the time you flipped the switch, it can separate a denied grant, another VPN taking over, or a node timeout.
  • Address: a local log endpoint, similar to http://192.168.x.x:port/api/log. Open it only on your own network. Do not post the full address in a chat or forum.
  • Network / routing table: whether the current interfaces and routes still point at Shadowrocket. If you drop immediately after connect, use this to see whether the system moved the routes away.
  • System proxy settings: confirm this app is still the one in effect. Check this first if several networking apps are installed.
Diagnostics
Diagnostics page

TUNNEL

The TUNNEL group in the screenshot. If the provider did not ask in writing, leave all three at their defaults.

Proxy

How the local proxy works with the tunnel

This changes how the system tunnel and the local proxy port work together. It is not Proxy / Config / Direct under Global Routing on Home. The names are close. Do not open the wrong one.

A typical result of random changes: the switch turns on, the status bar shows VPN, but some apps fail. Restore this item to default first, then compare with Global Routing on Home.

TCP

The transport used by most web and API connections

Browsing, subscription refresh, and most chat apps use TCP. For handshake failures or certificate / TLS errors, check the system date and time first, then the node type, port, and password. Do not start by changing TCP options.

Open this only when the provider wrote that you should (for example a specific transport or multiplexing). Write down the old value first. After you change it, verify with the same node and the same site.

UDP

Needed by some calls, games, and meetings

Think about UDP only when pages load but voice or a game fails. If the provider plan or node notes say UDP is not included, that failure is a configuration limit. Changing clients will not fix it.

Do not toggle UDP to “speed up the web.” It usually does not help ordinary browsing. Same as TCP: leave the default unless you have written instructions.

Other

Alerts

Whether to notify on connect or disconnect · Off in the screenshot

When it is on, connect and disconnect may show a system notification. That helps confirm “did it just drop?” Leave it off if you do not want lock-screen or banner noise.

Alerts do not repair a drop. For repeated disconnects, check VPN permission, whether another app took over, and whether the subscription expired. Turning alerts on is not a fix.

TUNNEL and Other on Settings home
Match TUNNEL and Other at the bottom of the screenshot