Skip to content

Connection

Run mode — VPN or proxy only

Android, Windows, Linux

Mode Behaviour
VPN (default) A system tunnel captures all device traffic.
Proxy only No tunnel is created. The app only runs local SOCKS/HTTP proxies; only apps explicitly pointed at those ports go through the connection.

Proxy-only mode is useful when another VPN or an MDM profile already owns the system VPN slot, or when only one application should be routed. It requires SOCKS or HTTP (below) to be enabled — otherwise the app refuses to start with an explanatory message rather than showing a misleading “connected” state.

Not available on iOS, tvOS and macOS. On Apple platforms the Xray core runs inside a Network Extension, which the system keeps alive only together with a VPN tunnel — remove the tunnel and no process is left to hold a local port. iOS also gives apps no way to set a system proxy. Local SOCKS/HTTP proxies do work on Apple platforms, but only while the tunnel is up (section 03).

Other connection settings

MTU

1280 · 1280–1500

All platforms

Leave at the default unless you have a reason to change it. Higher isn't automatically better: at 1500, large downloads can stall completely on some networks, because oversized packets are silently dropped rather than fragmented.

Preferred IP type

auto

All platforms

auto / ipv4 / ipv6. On auto the app routes IPv6 into the tunnel only when the device genuinely has IPv6 upstream — advertising IPv6 with no real upstream makes apps prefer AAAA records and then fail on anything routed directly.

Kill switch

off

All platforms

When enabled, disconnecting is blocked while the tunnel is active, so traffic can't silently fall back to the open network.

Silent reconnect

on

Android, iOS, tvOS, macOS

Restores the connection after an unexpected drop, without notifications (still written to the connection log). An explicit Connect always takes over the VPN slot even from another VPN app; a silent reconnect deliberately does not — if another VPN took the slot, SMProxy stands down.

Auto-connect

off

All platforms

Connects to the last used server when the app starts. Separate switches connect automatically on Wi-Fi or mobile data — see section 03d.

Launch at boot / login

off

Android · macOS · Windows · Linux

On Windows this requires the signed build (section 06). Not available on iOS and tvOS — the system doesn't permit apps to launch themselves.

“The server is not answering the handshake”

WireGuard / AmneziaWG · Android 400, iOS / macOS / tvOS 295, desktop 182 and later

When a WireGuard or AmneziaWG tunnel is up but the server stays silent, the main screen shows a banner: “The server is not answering the handshake — still retrying. If it never connects, contact your provider: keys, Endpoint and AmneziaWG parameters must match the server.”

  • Appears about 20–30 seconds after connecting; the app keeps retrying in the background.

  • Disappears on its own as soon as real traffic starts flowing, on disconnect, or when you switch servers.

  • The check is passive: the app reads its own traffic counters and never sends probe requests.

  • If the banner never goes away, the config does not match the server — wrong keys, Endpoint, or AmneziaWG obfuscation parameters (S1/S2, H1H4, Jc…). Ask your provider for a corrected config.