On Windows, installing and importing are quick. The part that decides whether the VPN actually works for you is one setting. A VLESS client can carry your traffic in two ways: as a system proxy or through a TUN virtual network adapter. Pick the wrong one and the browser goes through the VPN while your game, launcher or terminal does not. This guide explains both modes, the install, and the leftover-proxy problem that can leave a PC with no internet after a crash.
The worked example in Steps 1 and 2 is Kovra, the service that publishes this guide. The rest applies to any VLESS subscription.
What you need
- Windows 10 version 1809 or later, or Windows 11. That is Happ's stated minimum. To check, press Win + R, type
winverand press Enter. Version 1809 is OS build 17763. - Administrator rights for the install. Happ installs a background service that it uses to connect, including in TUN mode.
- A link created for this PC. Kovra binds each link to the first device that opens it, so your phone's link will not work here.
Step 1: get the link for this PC
In your Kovra dashboard, press Add device (or Connect if it is your first) and pick Windows. The new card holds the subscription link with a copy button. It uses one device slot. The 3-device plan has three, and an extra slot costs $5 for 30 days. Copy the link. How these links work, and why each one belongs to one device, is explained in VPN subscription links explained.
Step 2: install Happ from the official source
The dashboard's Happ button downloads setup-Happ.x64.exe from Happ's official GitHub releases page (Happ-proxy/happ-desktop). If your PC has an ARM processor, as some Snapdragon laptops do, download setup-Happ.arm64.exe from the same page instead. Settings, System, About shows the processor type under System type.
Run the installer and approve the User Account Control prompt. If SmartScreen shows "Windows protected your PC", check that the file came from that GitHub page before choosing More info and Run anyway. Do not use repackaged installers from download portals: a VPN client sees all your traffic, and a modified one could do anything with it.
Step 3: import the subscription
Copy the link, open Happ, use the + button and add the link from the clipboard. Happ's documentation lists the clipboard, a QR code and a deep link as the ways to add a subscription, and the exact labels shift a little between versions. The list of locations appears. Kovra asks Happ to refresh it every hour, so new locations arrive on their own.
If the link on your card starts with kovravpn.com/p/, it is a one-tap import page rather than a plain subscription address. Open it in a browser on this PC and let it open Happ, which then adds the subscription.
System proxy vs TUN: the one choice that matters
System proxy runs a small proxy on your own PC and points Windows' proxy setting at it. Apps that respect that setting, mainly browsers and some Microsoft apps, send their traffic through the VPN. Everything else connects directly: most games and launchers, command-line tools such as curl, git and package managers, and many chat and sync clients. Some Microsoft Store apps cannot use a proxy on your own PC at all, because Windows isolates them from it.
TUN adds a virtual network adapter and routes the system's traffic into it, so every app goes through the tunnel without knowing a VPN exists. It is the mode to use if anything other than a browser must be covered.
| System proxy | TUN | |
|---|---|---|
| Browsers | Covered | Covered |
| Games, launchers, CLI tools | Usually not covered | Covered |
| Browser WebRTC | Can reveal your real IP | Goes through the tunnel |
| Microsoft Store apps | Some cannot connect | Covered |
| Risk after a crash | A leftover proxy setting blocks browsing | No proxy setting is left behind |
In Happ desktop, the choice is a dropdown on the main screen. Proxy and TUN can be switched on separately or together, which Happ shows as Mixed. The same dropdown picks the TUN provider, and the tray menu lists the providers too. Since Happ 4.2.1 the default provider is Xray TUN; leave it unless you have a specific reason to change it. Happ's release notes also list a Per-App Proxy option when running Xray TUN, for keeping chosen apps outside the tunnel.
Administrator prompts, firewall and antivirus
Creating a network adapter needs administrator rights. Happ works through a background service installed with the app, so the administrator prompt normally comes once, at install time. If the service cannot start, current versions say so and suggest reinstalling. The release notes also mention a Reset action that repairs the service.
Windows Defender Firewall allows outgoing connections by default, so Happ normally needs no firewall rule. A firewall prompt usually appears only if you turn on LAN sharing, which Happ's release notes call Allow from LAN. That setting opens proxy ports to other devices on your network, so leave it off unless you need it. Third-party firewalls that filter outgoing traffic need to allow Happ.
Antivirus products sometimes flag proxy and VPN clients. Do not switch the antivirus off. Check the source instead. Happ's 4.2.1 release notes say the Windows installer now ships fully signed binaries, so look at the Digital Signatures tab in the Properties window of the flagged file. If the file came from the official GitHub page and shows a valid signature, report the false positive to the antivirus vendor or add an exclusion for that file only.
One VPN client at a time
Two clients fight over the same system proxy setting and the same routes, and the result is a connection that works on some sites and not others. Quit, or uninstall, other VPN and proxy apps before you connect. That includes other VLESS clients, "free VPN" browser extensions and proxy extensions. Corporate VPNs such as a work laptop's access client can override your routes entirely. On a managed PC, ask IT before installing anything. More on conflicting software is in another VPN, proxy or security app.
The leftover-proxy trap
In system proxy mode, Windows is told to send web traffic to a proxy on your own PC. If the client crashes, or is killed in Task Manager, that setting can survive the app. Windows keeps pointing browsers at a proxy that no longer exists, and nothing loads, even with the VPN off. The fix takes a minute:
- Open Settings, Network & internet, Proxy.
- Under Manual proxy setup, open the Use a proxy server entry and switch it off. On Windows 11 it sits behind a Set up or Edit button; save afterwards. On Windows 10 it is a toggle on the same page.
- Reload the page in your browser.
Recent Happ versions clear their own leftover proxy on startup, so opening Happ and disconnecting cleanly also fixes it. To prevent it, disconnect or quit from Happ's window or tray menu instead of ending the process.
Kill switch on Windows
A kill switch blocks all traffic when the tunnel drops, so nothing leaks through your normal connection during the gap. Android has one built into the system. Windows has no single switch that does this for an app like Happ, so on Windows it depends on the client. As of September 2026, Happ's documentation and desktop release notes do not describe a kill switch, so do not assume one. INCY's desktop readme lists a kill switch, but INCY labels its desktop client pre-alpha. The leak test guide shows how to check what your client actually does when the tunnel drops.
Verify
Connect, then check four things: your public IP matches the location you picked, DNS is not answered by your provider, IPv6 does not show your real address, and WebRTC in the browser does not reveal it either. WebRTC matters most in system proxy mode. The VPN leak test covers each check. If you are curious why VLESS is used here instead of WireGuard or OpenVPN, see the protocol comparison.
When it fails
| Symptom | Cause | Fix |
|---|---|---|
| A game or launcher ignores the VPN | System proxy mode; the app does not use proxy settings | Switch to TUN |
| No internet after closing or crashing the app | Leftover system proxy setting | Switch off Use a proxy server, or open Happ and disconnect cleanly |
| The only entry is "One device per link - kovravpn.com" | The link is bound to another device | Reset device binding on the card and refresh here, or use a separate link for this PC |
| The only entry is "No active plan - kovravpn.com" | The plan has ended | Renew; the list returns on the next refresh |
| TUN will not start | Often Happ's background service is not running | Use Happ's service reset or reinstall as administrator |
| Connected, but nothing loads | DNS, clock, network filtering or another client | Work through connected but no internet |
The placeholder entries ending in "kovravpn.com" point to a dummy local address. Connecting to one gives no internet by design, so switch to a real location once the cause is fixed.