Networking 5 min read

VPN Beginner's Guide: Subscriptions, Nodes, Protocols, Split Tunneling, Global & Rule Modes Explained

New to cross-border network services? This guide explains what a subscription link is, how nodes and route types differ, what protocol terms mean, and when to use split tunneling versus global or rule mode — read once and you're ready to go.

What is a subscription link? One URL for all your configuration

If you're new to cross-border network services, the first term you'll meet is the subscription link. In essence, it's a Base64-encoded string containing a set of node server addresses, ports, protocol types, and keys. Once your client imports the subscription, it parses the data and builds the node list automatically — no need to enter server details one by one.

How to import a subscription link

A subscription link usually starts with https:// followed by a long string of random characters, so it looks just like an ordinary URL. In your client, find 'Add Subscription' or 'Import from Clipboard', paste the link, and confirm — the node list appears in the sidebar. When the provider updates its routes later, one click on 'Update Subscription' syncs the new nodes automatically.

The import entry point varies slightly between clients: on desktop it's usually under the 'Subscription' menu, while on mobile it's often in 'Config' or 'Settings → Subscription'. If you can't find it, just search for 'subscription'.

A few clients support subscription conversion, which normalizes links from different protocols into a single format for use in specific clients. Beginners don't need it — just knowing it exists is enough.

Nodes and route types: direct, relay, or IEPL dedicated line?

A node is a server entry point located in a specific country or region. When choosing a node, the region determines the target network environment you access, while the route type determines the stability and cost of that link.

How the three route types differ

Route type Link characteristics Best for
Direct Connects directly to the server in the target region; short path, low latency Everyday browsing, light use
Relay Forwards through an intermediate node to bypass congested direct routes Long-distance cross-border traffic, stability first
IEPL dedicated line Enterprise-grade point-to-point line; stable during peak hours Remote work, video calls, streaming

The rule of thumb is simple: if it works, don't switch. When you hit frequent lag or disconnects, move up from direct to relay or dedicated lines. The route type is shown automatically in the node name after your client imports the subscription — no need to memorize parameters.

Take VPNYS's route pool as an example: popular entry points cover Hong Kong, the United States, Japan, Singapore, Italy, and more, with each region broken down into direct, relay, and IEPL dedicated lines.

Common targets include AI tools like ChatGPT, Claude, and Gemini, as well as streaming platforms such as Netflix and YouTube. These services check the IP's region strictly, so when picking a node, first make sure the region matches your target, then consider route stability.

110+countries & regions
190+routes
Unlimitedsimultaneous devices
14-daymoney-back guarantee

Protocol terms at a glance: SS, VMess, Trojan, VLESS, Hysteria2, TUIC

Protocols determine how data is encrypted and encapsulated. For users, the protocol is usually preconfigured in the subscription and recognized automatically by the client after import — no manual selection needed. Knowing the differences gives you direction when troubleshooting.

  • Shadowsocks (SS): the classic proxy protocol with encrypted transport and the broadest compatibility — supported by virtually every client.
  • VMess: a V2Ray-family protocol with built-in anti-blocking design and more configuration fields than SS.
  • VLESS: a lightweight evolution of VMess that strips redundant metadata, often paired with XTLS.
  • Trojan: disguises traffic as ordinary HTTPS over port 443, with few distinguishing characteristics.
  • Hysteria2: built on QUIC transport, performs well on weak networks and suits mobile connections.
  • TUIC: also QUIC-based, with low latency — a good fit for links with high packet loss.

No protocol is absolutely better than another — it's about matching the scenario. The protocol your provider recommends by default is usually the combination tested on the current route, so beginners can simply stick with it. If you switch protocols manually, note that the client needs to re-parse the subscription, and some nodes may require matching ports.

Split tunneling, global or rule mode: which one for daily use?

The mode determines which traffic goes through the proxy. Understanding this matters more than memorizing any parameter.

Global mode: all traffic through the proxy

Global mode is the simplest to configure — all traffic is forwarded through the proxy. But sites in mainland China also detour overseas, which slows things down and wastes data. It's fine for temporary troubleshooting, not for everyday use.

Rule mode: split traffic by domain and IP

Rule mode, also called split tunneling, routes traffic by domain and IP rules: international traffic goes through the proxy while mainland China traffic connects directly. It's the mainstream choice for daily use. Clients usually ship with a built-in rule set covering common mainland domains going direct, international streaming through the proxy, and ad or tracker domains blocked.

Custom rules: save them for later

Rules can be customized, but beginners shouldn't edit rule files right away — get the default config working first. If a site won't open, troubleshoot in this order: switch nodes first, then check whether the domain matches a direct rule, and finally switch to global mode temporarily to verify.

Beginner details often overlooked: DNS leaks and five common mistakes

A DNS leak means domain resolution requests bypass the proxy and are visible to your local network. Most clients offer a 'Remote DNS' or 'Anti-leak' option; when enabled, DNS resolution and data traffic share the same proxy path. In rule mode, mainland domains resolving locally and international domains resolving remotely is by design, not a leak.

Besides DNS, these five details are the most common questions from beginners:

  • ❌ Screenshotting your subscription link into a group chat or public forum — the link is your account key, and once leaked, others will burn through your data.
  • ❌ Leaving the client in global mode with auto-start enabled — mainland traffic detours overseas, slowing things down and wasting data.
  • ✅ Updating the subscription before switching nodes — old nodes may be retired; if you can't connect, check whether your list is stale.
  • ✅ Keeping rule mode as the default — mainland direct, international via proxy, balancing speed and availability.
  • ✅ Signing up with just a username and password — VPNYS doesn't require an email address, reducing your exposure.

Wrapping up: get it working first, optimize later

The right path for beginners: import the subscription → choose rule mode → pick routes by scenario. Direct or relay is fine for everyday browsing; for remote work, video calls, and streaming, prioritize IEPL dedicated lines. When problems arise, troubleshoot in this order — update subscription → switch nodes → temporarily switch to global — and most issues will be resolved.

The subscription link is the entry point, nodes are the path, protocols are the encapsulation, and modes are the routing strategy. Beginners only need to remember three things: import the subscription, keep rule mode as the default, and pick route types by scenario. VPNYS offers 110+ countries / 190+ routes, unlimited simultaneous devices, a 14-day money-back guarantee, and no email required at signup — a solid choice to start with.

Start Free