The four steps of day one
The trouble people run into as VPN beginners usually isn't the client itself — it's the half hour after checkout: how to create an account, where to grab the subscription link, and how to confirm the import took effect. Whether you're after cross-border access, overseas streaming, or reaching your usual services while traveling, the workflow is the same. This guide follows day one in chronological order, describing each step, what you should see, and where to look first if you get stuck. There are four steps in total, and once you know them you can finish in under ten minutes.
- Create an account: sign up with a username and password — no email address needed — and you land straight in the user panel.
- Choose a plan and pay: pick a monthly plan or a data pack based on your usage, and pay with Alipay, WeChat, or USDT.
- Get the subscription link and import it: copy the subscription link from the panel, paste it into the client for your platform, and let the client pull the server list.
- Verify the connection: confirm the server list, latency figures, and actual browsing all look right, then set up routing rules to suit your habits.
Steps three and four are where things most often go wrong. An incompletely copied subscription link, a link pasted into the wrong field, and routing rules sending the domain you need to a direct connection — these three account for most beginner reports. Each section below states what you should see, so you can check against it.
110+
Countries / regions covered
210+
Available routes
14 days
No-questions-asked refund window
Unlimited
Simultaneous devices
Step 1: Create an account with a username, no email needed
Signing up is shorter than most people expect. A VPNBN account needs only a username and password — no email address — and there's no verification email to wait for: submit the form and you're in the user panel, where your plan, subscription, and usage all live. For first-timers, that removes the most error-prone stretch of the process — verification mails landing in spam, expired links, mistyped addresses simply don't happen.
Two things to keep in mind when creating your account:
- Save your username and password somewhere safe. You'll use them to sign in to the panel, fetch the subscription link, and check remaining data, so store them in a password manager rather than relying on memory.
- Don't use your real name or your usual email prefix as the username. It's the account's only identifier, so picking something unrelated to your identity saves trouble later.
Once the account is created, the panel shows a few entries: plan and usage, subscription link, client downloads, and support tickets. On day one you only need the first three. If the plan and usage page loads normally, step one is done.
Step 2: Choose a plan and pay
Plans come in two kinds: monthly data plans and one-off data packs. Monthly plans reset their data allowance each month on the activation date; data packs are bought outright and never expire, drawing down only what you use — a good fit if your usage varies. Both are activated from the same panel, and payment works the same way: Alipay, WeChat, or USDT. Here are the tiers currently on sale:
| Type | Data | Price | Best for |
| Monthly | 60GB | ¥9.9 / month | Occasional research and email, light use on a single device |
| Monthly | 250GB | ¥18 / month | Daily video streaming, regular use across several devices at once |
| Monthly | 500GB | ¥28 / month | Always-on connections, multiple devices at home |
| Data pack | 300GB | ¥158 | Irregular usage, occasional heavy days |
| Data pack | 1000GB | ¥358 | Intensive use during business trips or travel |
| Data pack | 3000GB | ¥658 | Long-term backup, no expiry date |
Once payment goes through, the usage stats in the panel update immediately and the plan status shows as active — that's what step two should look like. If the status still says pending after paying, refresh the panel once; if it doesn't change, open a ticket with your order number and it's usually handled within minutes.
Not sure about usage? Start small
If you don't know how much data you'll use in a month, start with the ¥9.9 60GB monthly plan for a week or two — the panel shows your actual consumption rate, and you can decide whether to move up a tier. Data packs never expire, so buying extra isn't wasted; keep it as a backup.
Every plan is covered by a 14-day no-questions-asked refund. In other words, the cost of trial and error on day one has a ceiling: if it doesn't suit you after a few days, request a refund within 14 days — no need to agonize before you order.
Step 3: Get the subscription link and import it into your client
The subscription link is the heart of the whole process. It's an address starting with https:// and ending with a token unique to your account. Once the client has it, it periodically pulls the latest server list from the server — when routes are added or removed, you don't have to change anything by hand; the client syncs on its own.
Compared with adding individual servers manually, a subscription saves effort: server addresses, ports, and encryption methods are filled in for you, and the client matches them automatically after reading the subscription. Routes in a subscription may use different transport protocols — commonly Shadowsocks, VMess, Trojan, VLESS, Hysteria2, TUIC, and others — and the client connects using the protocol each route specifies. Ordinary users don't need to understand the differences; just pick the route with the lowest latency.
General import steps
- In the panel, find the subscription link and click the copy button. The link is long, so don't select and copy it by hand — that's how characters get dropped.
- Open the VPNBN download page, get the client for your platform, and install it. Windows, macOS, iOS, Android, and Linux all have builds.
- Open the client, find the subscription or configuration entry, paste the link in, and save.
- Click update subscription once. The client pulls the server list, and within a few seconds you should see nodes across 110+ countries / 210+ routes, each with a latency figure.
- Select a route and click connect. On the first connection the system asks for permission once — just allow it.
A subscription link is account credentials
Your subscription link carries your token, so anyone who has it can use your data. Don't post it in group chats or on public pages. If you suspect it leaked, reset the subscription token in the panel — the old link stops working immediately, and you just import the new one.
Client differences by platform
The clients look different across the five platforms, and so does what you see on the first connection:
| Platform | Connection method | What you'll see on first connect |
| Windows | Desktop client, supports both system proxy and virtual network adapter modes | Enabling virtual adapter mode triggers a one-time administrator permission prompt |
| macOS | Desktop client, same as above | You need to allow the network extension in system settings |
| iOS | Mobile app, connects through the system VPN configuration | An "Add VPN Configuration" confirmation dialog appears |
| Android | Mobile app, connects through the system VpnService | A connection authorization dialog appears |
| Linux | Command line or desktop client | Creating the virtual network adapter requires root or equivalent permissions |
Two details worth knowing up front:
- Windows and macOS offer two ways to take over traffic. System proxy mode only affects programs that read the system proxy settings — browsers are usually fine; virtual network adapter (TUN) mode takes over all traffic on the machine, including software that ignores the system proxy. If some app isn't going through a route on day one, switch to virtual adapter mode first.
- iOS and Android both connect through the VPN interface provided by the system, so a VPN indicator appears in the status bar while connected — that's normal. It disappears automatically once you disconnect.
Step 4: Verify the connection, and read latency and routing
A successful connection doesn't mean the configuration is right. The client showing "connected" only means the tunnel is up; whether traffic is going where you expect needs three checks: the server list updates, the target site opens, and the exit address has actually changed. Go through these one by one:
- ✅ The client shows the full server list, with a latency figure after each route.
- ✅ A page that's only reachable overseas loads normally.
- ✅ An exit IP lookup shows the region the server is in, not your local one.
- ❌ It says connected but pages won't load: switch to global mode and try again. If global mode works, the problem is in your routing rules.
- ❌ Latency figures stay blank: switch to another route and update once, then check the client log for errors.
How to choose routing rules
Routing rules decide which traffic goes through a route and which connects directly. Clients generally offer three modes:
- Rule mode: decides by domain and IP — sites in mainland China connect directly, while traffic that needs a route goes through one. Use this for everyday work; mainland China sites don't take a detour and speed isn't affected.
- Global mode: all traffic goes through a route. Useful for quick troubleshooting, or when a program's routing decision is off.
- Direct mode: nothing goes through a route — effectively turning acceleration off for now. Handy when switching routes or testing your local network.
Rule mode relies on the client's built-in rule set, usually matching by domain suffix and IP range. If a site that needs a route is being sent to a direct connection, add a domain rule for it in the client, or switch to global mode temporarily. Conversely, if a mainland China cloud drive is being routed through a node and ends up slower, add it to the direct list.
Take a look at the DNS settings
A DNS leak means traffic goes through a route, but domain lookups are still sent to your local ISP's DNS servers. The connection itself is fine, yet some services still respond based on your local location — you'll see it as "some sites open, others spin forever." Most clients resolve on the server side by default, or offer switches like "DNS leak protection" or "remote DNS." The day-one check is simple: leave the client's default DNS handling alone and don't change anything extra.
Route types and latency figures
Three common route types in the list:
- IEPL dedicated line: runs over an international Ethernet private line, bypassing the public internet's international gateways, so latency is steadier and evening-peak fluctuations are smaller.
- Relay: connects first to an entry point in mainland China, which forwards to an overseas exit. More stable than a direct connection, and cheaper than a dedicated line.
- Direct: the client connects straight to an overseas server; latency depends on your local network and international gateway conditions, and fluctuates the most.
The latency figure in the client is the round-trip time from your machine to the server — it only tells you how fast that leg is, not that websites will necessarily load quickly. The recommended order for picking routes: try a dedicated line first, fall back to a relay when latency is clearly high, and keep direct connections as a backup. After switching routes, test again; once the number is stable and stops jumping around, you can settle on it.
When it won't connect, check these first
In rough order of how often they come up, check these first:
Subscription update fails
- Is the link complete? Copy it again with the copy button, and make sure there are no extra spaces at either end.
- Is it pasted in the right place? It goes in the subscription or configuration field, not the address bar for adding a server manually.
- Is the system clock accurate? A large time offset makes token validation fail — turn on automatic time sync.
Connects, but pages won't open
- Switch to global mode and try again. If global mode works and rule mode doesn't, the problem is in the routing rules — add a rule for that domain.
- Switch to another route. A route being temporarily unavailable is normal, and switching tells you whether the route is the problem.
- Check the DNS options and restore the client's defaults.
- If none of that helps, disconnect and reconnect; if it still fails, restart the client.
Speed isn't what you expected
- Look at two metrics together: the latency figure and how fast a video page actually loads. When they disagree, trust the latter.
- Try a different route type: when a direct connection fluctuates, switch to a relay or dedicated line.
- Make sure no other device is saturating the bandwidth. Device count is unlimited, but many devices running flat out at once will affect each other.
Token invalid or subscription expired
Reset the subscription token once in the panel and import the new link into your client. The old link stops working the moment you reset, which also clears up any worry about a shared link.
Wrapping up day one and common pitfalls
By this point there are really only two things to confirm: the subscription updates normally, and your usual sites open normally. The rest — routing details, route types, protocol differences — can be tuned over the next few days; you don't need to understand it all on day one.
The minimum bar for day one: the client shows the server list and connects successfully, your usual sites open normally, and the panel shows data being consumed. Meet all three and you can get back to what you were doing; if not, work through the previous section in order, or open a ticket with the client log attached.
Finally, a few pitfalls beginners hit often — avoid them up front:
- Switching routes constantly. Every switch means a new handshake, and bouncing between routes in a short window makes things worse. Stick with one for a day, then change if it doesn't fit.
- Putting every device on it. Device count is unlimited, but there's no need to route your smart speaker or TV box through it. Go by actual need and your routing stays clearer.
- Forgetting the refund window. The 14-day no-questions-asked refund counts from the payment date, so if it doesn't suit you after a few days, deal with it early rather than on the last day.
- Saving the subscription link like an ordinary URL. It's equivalent to account credentials — browser bookmarks and chat history are both bad places for it. Clear it after use.
If you want more detail, see the client configuration notes in the Beginner's Guide, or check the route list on the Global Servers page. For anything this article doesn't cover, the ticket entry in the panel is the fastest route.