How to Set Up a VPN on Windows 11 and 10: TUN vs System Proxy

SetupUpdated October 2, 20268 min read

On Windows, installing and importing are quick. The part that decides whether the VPN actually works for you is one setting. A VLESS client can carry your traffic in two ways: as a system proxy or through a TUN virtual network adapter. Pick the wrong one and the browser goes through the VPN while your game, launcher or terminal does not. This guide explains both modes, the install, and the leftover-proxy problem that can leave a PC with no internet after a crash.

The worked example in Steps 1 and 2 is Kovra, the service that publishes this guide. The rest applies to any VLESS subscription.

What you need

  • Windows 10 version 1809 or later, or Windows 11. That is Happ's stated minimum. To check, press Win + R, type winver and press Enter. Version 1809 is OS build 17763.
  • Administrator rights for the install. Happ installs a background service that it uses to connect, including in TUN mode.
  • A link created for this PC. Kovra binds each link to the first device that opens it, so your phone's link will not work here.

Step 1: get the link for this PC

In your Kovra dashboard, press Add device (or Connect if it is your first) and pick Windows. The new card holds the subscription link with a copy button. It uses one device slot. The 3-device plan has three, and an extra slot costs $5 for 30 days. Copy the link. How these links work, and why each one belongs to one device, is explained in VPN subscription links explained.

Step 2: install Happ from the official source

The dashboard's Happ button downloads setup-Happ.x64.exe from Happ's official GitHub releases page (Happ-proxy/happ-desktop). If your PC has an ARM processor, as some Snapdragon laptops do, download setup-Happ.arm64.exe from the same page instead. Settings, System, About shows the processor type under System type.

Run the installer and approve the User Account Control prompt. If SmartScreen shows "Windows protected your PC", check that the file came from that GitHub page before choosing More info and Run anyway. Do not use repackaged installers from download portals: a VPN client sees all your traffic, and a modified one could do anything with it.

Step 3: import the subscription

Copy the link, open Happ, use the + button and add the link from the clipboard. Happ's documentation lists the clipboard, a QR code and a deep link as the ways to add a subscription, and the exact labels shift a little between versions. The list of locations appears. Kovra asks Happ to refresh it every hour, so new locations arrive on their own.

If the link on your card starts with kovravpn.com/p/, it is a one-tap import page rather than a plain subscription address. Open it in a browser on this PC and let it open Happ, which then adds the subscription.

System proxy vs TUN: the one choice that matters

System proxy runs a small proxy on your own PC and points Windows' proxy setting at it. Apps that respect that setting, mainly browsers and some Microsoft apps, send their traffic through the VPN. Everything else connects directly: most games and launchers, command-line tools such as curl, git and package managers, and many chat and sync clients. Some Microsoft Store apps cannot use a proxy on your own PC at all, because Windows isolates them from it.

TUN adds a virtual network adapter and routes the system's traffic into it, so every app goes through the tunnel without knowing a VPN exists. It is the mode to use if anything other than a browser must be covered.

System proxyTUN
BrowsersCoveredCovered
Games, launchers, CLI toolsUsually not coveredCovered
Browser WebRTCCan reveal your real IPGoes through the tunnel
Microsoft Store appsSome cannot connectCovered
Risk after a crashA leftover proxy setting blocks browsingNo proxy setting is left behind

In Happ desktop, the choice is a dropdown on the main screen. Proxy and TUN can be switched on separately or together, which Happ shows as Mixed. The same dropdown picks the TUN provider, and the tray menu lists the providers too. Since Happ 4.2.1 the default provider is Xray TUN; leave it unless you have a specific reason to change it. Happ's release notes also list a Per-App Proxy option when running Xray TUN, for keeping chosen apps outside the tunnel.

Administrator prompts, firewall and antivirus

Creating a network adapter needs administrator rights. Happ works through a background service installed with the app, so the administrator prompt normally comes once, at install time. If the service cannot start, current versions say so and suggest reinstalling. The release notes also mention a Reset action that repairs the service.

Windows Defender Firewall allows outgoing connections by default, so Happ normally needs no firewall rule. A firewall prompt usually appears only if you turn on LAN sharing, which Happ's release notes call Allow from LAN. That setting opens proxy ports to other devices on your network, so leave it off unless you need it. Third-party firewalls that filter outgoing traffic need to allow Happ.

Antivirus products sometimes flag proxy and VPN clients. Do not switch the antivirus off. Check the source instead. Happ's 4.2.1 release notes say the Windows installer now ships fully signed binaries, so look at the Digital Signatures tab in the Properties window of the flagged file. If the file came from the official GitHub page and shows a valid signature, report the false positive to the antivirus vendor or add an exclusion for that file only.

One VPN client at a time

Two clients fight over the same system proxy setting and the same routes, and the result is a connection that works on some sites and not others. Quit, or uninstall, other VPN and proxy apps before you connect. That includes other VLESS clients, "free VPN" browser extensions and proxy extensions. Corporate VPNs such as a work laptop's access client can override your routes entirely. On a managed PC, ask IT before installing anything. More on conflicting software is in another VPN, proxy or security app.

The leftover-proxy trap

In system proxy mode, Windows is told to send web traffic to a proxy on your own PC. If the client crashes, or is killed in Task Manager, that setting can survive the app. Windows keeps pointing browsers at a proxy that no longer exists, and nothing loads, even with the VPN off. The fix takes a minute:

  1. Open Settings, Network & internet, Proxy.
  2. Under Manual proxy setup, open the Use a proxy server entry and switch it off. On Windows 11 it sits behind a Set up or Edit button; save afterwards. On Windows 10 it is a toggle on the same page.
  3. Reload the page in your browser.

Recent Happ versions clear their own leftover proxy on startup, so opening Happ and disconnecting cleanly also fixes it. To prevent it, disconnect or quit from Happ's window or tray menu instead of ending the process.

Kill switch on Windows

A kill switch blocks all traffic when the tunnel drops, so nothing leaks through your normal connection during the gap. Android has one built into the system. Windows has no single switch that does this for an app like Happ, so on Windows it depends on the client. As of September 2026, Happ's documentation and desktop release notes do not describe a kill switch, so do not assume one. INCY's desktop readme lists a kill switch, but INCY labels its desktop client pre-alpha. The leak test guide shows how to check what your client actually does when the tunnel drops.

Verify

Connect, then check four things: your public IP matches the location you picked, DNS is not answered by your provider, IPv6 does not show your real address, and WebRTC in the browser does not reveal it either. WebRTC matters most in system proxy mode. The VPN leak test covers each check. If you are curious why VLESS is used here instead of WireGuard or OpenVPN, see the protocol comparison.

When it fails

SymptomCauseFix
A game or launcher ignores the VPNSystem proxy mode; the app does not use proxy settingsSwitch to TUN
No internet after closing or crashing the appLeftover system proxy settingSwitch off Use a proxy server, or open Happ and disconnect cleanly
The only entry is "One device per link - kovravpn.com"The link is bound to another deviceReset device binding on the card and refresh here, or use a separate link for this PC
The only entry is "No active plan - kovravpn.com"The plan has endedRenew; the list returns on the next refresh
TUN will not startOften Happ's background service is not runningUse Happ's service reset or reinstall as administrator
Connected, but nothing loadsDNS, clock, network filtering or another clientWork through connected but no internet

The placeholder entries ending in "kovravpn.com" point to a dummy local address. Connecting to one gives no internet by design, so switch to a real location once the cause is fixed.

Frequently asked questions

Does Happ run on Windows 7 or 8?

Current Happ desktop builds need Windows 10 version 1809 or later, or Windows 11. Happ keeps an old Legacy build, 1.0.2, for older systems, but it is a frozen version, and Windows 7 and 8.1 no longer receive security updates from Microsoft. Upgrading Windows is the better fix.

Is there a Linux option?

Happ publishes Linux builds, but Kovra's dashboard has no Linux device type today, and this guide does not cover Linux.

Can I use v2rayN instead of Happ?

v2rayN is an open-source desktop client that imports subscription links, and it can read the same link. Kovra's dashboard and support instructions are written for Happ, so you would be following v2rayN's own documentation for its modes and settings. One link still belongs to one device.

Do I need to keep Happ open for the VPN to work?

The tunnel runs while Happ and its background service are running. Happ has a tray icon with a menu, so the main window does not need to stay on screen. When you want the VPN off, disconnect or quit from Happ itself rather than ending the process in Task Manager, so the app can clean up the system proxy it set.

Why does my game ignore the VPN?

Most games, launchers and anti-cheat services connect directly and ignore Windows proxy settings, so in system proxy mode their traffic never enters the tunnel. Switch Happ to TUN mode, which captures traffic from every app through a virtual network adapter.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches