BEGINNER GUIDE
Guides About 9 min read

VPN beginners’ most common 10 questions, answered in one guide

Can you use a VPN on multiple devices? How is data counted? Will speeds be limited? Does it need to stay connected? Here are 10 practical answers covering how subscription services work before and after you start using one.

The 10 questions VPN beginners ask most often go beyond “how do I connect?” Device sharing, data usage, fluctuating route performance, and the right client-and-protocol combination all affect the experience. Understand these basics before choosing a plan or route.

This guide follows a practical order: understand the service, configure it, assess speed, use it over time, and troubleshoot problems. It covers subscription links, Shadowsocks, VMess, Trojan, VLESS, Hysteria2, TUIC, IEPL dedicated lines, DNS leaks, and split tunneling for first-time subscribers and users who are connected but still unsure how everything works.

The basics: what the service actually changes

Question 1: What can a VPN do—and what can’t it do?

Once connected, some or all of a device’s network requests pass through an encrypted tunnel before reaching the destination through the selected node. Websites typically see the node’s exit IP rather than the device’s original public IP. This route change can support cross-border access, protect data on public networks, and give specific apps a network exit in another region.

A successful connection does not mean every website will work. A destination service may check account details, the reputation of the exit IP, the browser environment, location permissions, or previous login regions. Local networks can also have packet loss, restricted UDP, or DNS issues. A VPN handles the transport path; it cannot change an account’s status or eliminate latency caused by physical distance.

Bottom line: It is more accurate to think of a VPN as a network channel with a selectable exit. Identify whether the problem is local networking, the transport route, the exit node, or the destination service instead of blaming every issue on the client.

Question 2: How are subscriptions, nodes, protocols, and clients related?

A subscription service provides node configurations, and the subscription link is how a client retrieves them. After reading the subscription, the client displays node names, server addresses, ports, protocols, and required authentication details. The node determines where traffic enters and exits, the protocol determines how data is packaged and transported, and the client establishes connections, refreshes subscriptions, and applies split-tunneling rules.

A subscription link is not an ordinary web address and should not be shared publicly. It often contains credentials used to identify the subscription. Copy it in full without deleting parameters manually. If importing fails, copy it again from the user panel and check whether the client supports that subscription format. Pasting only a server address is usually not enough to complete the setup.

Clients and protocols: how to choose

Question 3: How do you choose between Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC?

There is no universal ranking that applies outside a specific network environment. Shadowsocks is relatively straightforward and has a mature ecosystem. VMess and VLESS are common in clients that support routing and multiple transport combinations. Trojan typically runs over a TLS connection. Hysteria2 and TUIC place more emphasis on UDP- or QUIC-based transport and may behave differently on high-latency or somewhat lossy links.

Protocol Key characteristics What to check
Shadowsocks Widely implemented with a relatively straightforward configuration Client encryption compatibility and subscription updates
VMess / VLESS Supports multiple transport methods and routing capabilities Whether the transport layer, TLS, and client core version match
Trojan Typically carries data over a TLS connection Certificate domain, system time, and TLS handshake status
Hysteria2 / TUIC UDP- or QUIC-based, designed for challenging links Whether the current network allows stable UDP communication

If the client has generated nodes automatically from a subscription, use the complete configuration supplied by the service instead of changing parameters based only on the protocol name. When UDP is unstable on a particular network, Hysteria2 or TUIC may reconnect frequently; results may reverse on a network with better support. Choose based on compatibility and real-world stability, not theoretical peak speed.

Question 4: How do clients differ across platforms?

Windows and macOS clients typically let you switch between system proxy and TUN modes. System proxy mode mainly handles apps that follow the system proxy settings; some games, command-line programs, and apps with their own network stacks may bypass it. TUN mode creates a virtual network interface and covers more traffic, but is more likely to conflict with firewalls, virtual machines, enterprise security software, or other network tools.

Android commonly uses the system VPN interface to handle traffic and can decide which apps use the proxy. iOS and iPadOS are constrained by the system extension model, so background behavior and rule support depend on the client. TV boxes usually favor simpler operation, but may offer limited subscription import, log viewing, and rule editing. If the browser works but other apps do not, check the traffic-capture mode before switching nodes.

Devices and data: how sharing is counted

Question 5: Can multiple devices be used at the same time?

Simultaneous use depends on a plan’s device policy, not how many times the client is installed. Some services limit concurrent connections, some limit bound devices, and others allow unlimited devices. 87VPN plans support unlimited devices, so the same subscription can be used on computers, phones, tablets, and TV boxes. Keep the subscription link and account credentials secure when sharing.

Unlimited devices does not mean every device will maintain the same speed while sharing one physical connection. Household upload and download capacity, router performance, and Wi-Fi signal quality can all become shared bottlenecks. If several devices are downloading, backing up, or streaming high-bitrate content, pause high-traffic tasks and test again to determine whether the issue is local bandwidth contention or the remote route.

Question 6: How is data usage calculated, and does it continue after closing a webpage?

Subscription data usage is usually tied to the data transferred through the node. Whether downloads and uploads are combined depends on the plan description and the statistics shown in the panel. Video buffering, system updates, cloud sync, photo backups, game updates, and background app refreshes can all use data, so usage cannot be estimated from time spent actively browsing alone.

Closing a browser tab does not stop other apps from maintaining connections. While the client remains connected, background requests that match proxy rules may continue through the node. To identify the source, pause sync and automatic updates, then check the system’s per-app network statistics. 87VPN data bundles do not expire, making them suitable for irregular use; monthly plans are better for steady, predictable demand.

Speed and routes: how to find the bottleneck

Question 7: Will speeds be limited, and why can a speed test be fast while webpages are slow?

Speed depends on several links: the device to the router, the local ISP to the entry point, the entry point to the exit, the exit to the destination, and the destination’s own response time. Speed tests usually choose high-capacity servers and focus on sustained transfers. Webpage loading also involves DNS lookups, connection setup, TLS handshakes, and many small-file requests, so test results and real-world responsiveness do not always match.

Check the plan page and user panel for any plan-level speed limits; do not draw conclusions from a single test. Evening slowdowns may also come from local congestion, wireless interference, cross-border route fluctuations, or throttling by the destination. A more reliable method is to keep the device, local network, and destination the same while changing only one variable at a time.

  1. Disconnect the client first and confirm that the local network can reliably reach commonly used websites.
  2. Connect to a nearby node and test whether both ordinary webpages and the destination service open.
  3. Keep the node unchanged, then try system proxy and TUN modes separately to compare traffic capture.
  4. If UDP performs poorly on the current network, test again with a non-UDP option.
  5. Check the client logs to distinguish DNS failures, connection timeouts, TLS errors, and authentication failures.

Question 8: What is the difference between IEPL dedicated lines, transit routes, and direct connections?

A direct connection links the device straight to the remote node over the public internet. The path is simple, but cross-network and cross-border quality depends heavily on ISP routing. A transit route connects to a nearby entry point first, after which the service arranges the remaining transport to avoid some poor public-internet paths. An IEPL dedicated line generally refers to an international Ethernet-style private connection carrying a particular link between the entry and exit points; the device-to-entry and exit-to-destination segments may still use ordinary networks.

So “dedicated line” should not be understood to mean an independent route from the device to the website end to end, nor does it guarantee the lowest latency in every region or at every time. For destinations in Asia, a nearby exit is often better for interactive use. For services in Europe or North America, focus on the network relationship between the exit and the destination. Geography is only a reference; actual routing and packet loss matter more.

Route selection: For everyday browsing, start with a stable node at a reasonable distance. If a specific service has a regional or routing issue, adjust based on the destination’s location. Do not judge a node by its name alone, and do not keep switching routes when the connection is already working.

Connection strategy: does it need to stay on?

Question 9: Should a VPN stay connected all the time?

Whether to keep it on depends on the use case. Staying connected can reduce repeated switching on public networks, during sustained access to international services, or when a fixed exit is needed. For selected apps only, split tunneling usually saves data and prevents local websites, printers, online banking, or LAN devices from being sent to a remote node unnecessarily.

Split-tunneling rules can use domains, IPs, app processes, or rule sets to determine whether traffic goes direct or through the proxy. Support varies by client. Rule mode suits everyday use, while global mode is useful for temporary diagnosis: if global mode works but rule mode does not, inspect rule matching; if neither works, continue checking the node, protocol, DNS, and local network.

After sleep and wake, switching Wi-Fi networks, or changes to mobile connectivity, the client may still show as connected even though the underlying session has expired. Disconnect and reconnect, then test whether the exit IP has changed. For long-term use, refresh the subscription and client core regularly because server configuration, certificates, and protocol implementations can change during maintenance.

Privacy and troubleshooting: what to confirm before you start

Question 10: What is a DNS leak, and what should you prepare for setup and troubleshooting?

DNS converts domain names into reachable addresses. A DNS leak occurs when queries that should be handled by the tunnel or a specified resolver are still sent through the local network’s default DNS. This can expose where queries are going or produce results inconsistent with the node’s exit region, leading to the wrong site region, connection timeouts, or unexpected rule matching.

Enabling remote DNS, encrypted DNS, or TUN traffic capture does not guarantee a correct configuration. Also check for other network tools, browser-built-in resolution, enterprise network policies, or leftover virtual adapters. During testing, check both the exit IP and the DNS resolution path; a changed IP alone does not prove that every domain query uses the intended channel.

87VPN registration requires no email address; a username and password are enough. Then open the user panel to choose a plan, get the client, and copy the subscription link. On the first connection, do not change the protocol, DNS, split tunneling, and system proxy all at once, since multiple changes make the cause harder to isolate. Plans include a 30-day no-questions-asked refund, so you can test compatibility on your actual devices and usual networks.

If the logs show an authentication failure, refresh the subscription and confirm the plan status first. For a connection timeout, try another route or protocol. If only one website has problems, check the destination service, split-tunneling rules, and DNS. If every node fails, work through the local network, firewall, and system time. When contacting support, provide the OS, client name, symptoms, and tests already performed; that is more useful than simply saying “it won’t connect.”

For beginners, remembering every protocol parameter matters less than following a clear troubleshooting order: check the local network, then client traffic capture, then the node and protocol, and finally the destination service. Change one condition at a time and most connection, speed, and split-tunneling issues can be identified accurately.

First Month Free