Related guides
Which Connection Method to Choose
Updated
One RoyalShield account offers six connection methods: private network (Tailscale), Cisco (AnyConnect), OpenVPN, web proxy, Hiddify and router. None is best on every network — the one that resists packet loss best runs on UDP and becomes the worst on a campus network that throttles UDP; the most stable one covers only the browser; the most convenient one needs a premium account. This guide puts all six in one table with strengths, costs and best use, then recommends by carrier and by device. One rule to remember: switch any time on the same account — if one fails, try another.
The six methods in one table
- Private network (Tailscale): log in once and stay online, switch region from the menu, devices on one account reach each other (a home NAS). Cost: runs on UDP, so it falls back to relays on UDP-throttled campus networks, and it fights another VPN over DNS. Best for many devices and set-once-and-forget.
- Cisco AnyConnect: TLS, indistinguishable from an HTTPS visit, best compatibility and steadiest on restricted networks; official or built-in client, no configuration import. Cost: all traffic takes the route, so inside China you run the split-routing script separately. Best for work laptops, iPhones, old devices and UDP-restricted networks.
- OpenVPN: one .ovpn file, import and connect; nearly every OS, router firmware and NAS has a client, and it can start at boot. Cost: UDP; on phones and laptops it is less convenient than the two above. Best for OpenWrt routers, Synology/QNAP NAS and Linux servers.
- Web proxy: only the browser takes the route, request by request with no long-lived connection, so it never drops; no client, no admin rights. Cost: browser only — video apps, games and system DNS bypass it. Best for work laptops, machines already on a corporate VPN, and unstable broadband.
- Hiddify: the hysteria2 protocol resists packet loss and is fastest on lossy networks; QR-code import, one app on all five platforms, split routing built in. Cost: UDP, so it fails on UDP-restricted networks, and Windows antivirus often flags it, needing an exclusion. Best for speed and lossy broadband.
- Router: the whole LAN takes the route; TVs, boxes, consoles and grandparents’ phones install nothing; the firmware has split routing and auto-updates. Cost: a flashable router or a pre-installed unit, and router access needs a premium account. Best for households, offices and devices that cannot run a client.
Pick the region by your carrier
The same method can differ several-fold in speed between regions because of your carrier’s exit to that region, not the server. Northern China Unicom: try Japan and Korea first; southern China Telecom: Southeast Asia (Singapore, Malaysia, Thailand, the Philippines, Indonesia) or Australia; other carriers (Mobile, Great Wall): the China entry — the client connects only to a domestic address and we handle the cross-border leg, so cross-border interference does not reach you.
The red/yellow/green light on the region list shows each region’s live load; among several Japan servers, take the green one. Everyone is slow at the 8–11 pm national peak, and changing region then helps more than reconnecting.
Pick by scenario
- One phone, travelling: Cisco or Hiddify — scan a code or enter an address and go.
- A company laptop with no admin rights: the web proxy; also the web proxy if you can install clients but a corporate VPN is already running.
- Dormitory or office network that throttles UDP: Cisco. Hiddify, Tailscale and OpenVPN all use UDP and will be slow or drop.
- Broadband that keeps dropping, poor Wi‑Fi: the web proxy — there is no connection to drop.
- Speed on lossy broadband (old buildings, mobile data): Hiddify.
- Many devices, configure once, a home NAS to reach from outside: the private network.
- Whole household, TVs, boxes, grandparents’ devices, an office: the router (premium account).
- A router that cannot be flashed but a NAS or Linux box at home: put the OpenVPN profile on that device.
- Watching Chinese video from abroad: any method with the China region; the three device-wide methods block IPv6 on the route side, while the web proxy cannot control IPv6 and is unsuitable for video.
Split routing: Chinese sites direct, others through the route
Only users inside mainland China need split routing; users abroad should use full mode, since splitting sends some sites the long way round. Hiddify switches to “auto split” in the client, the web proxy in the extension, router firmware splits by default; Cisco and OpenVPN route everything after connecting and need the split-routing script from the Cisco section.
If a site fails in split mode, test in full mode first: if it opens, it is not on the list; if it still fails, the site itself is the problem.
When it fails, switch in this order
- Change region first. If another region connects, that one server is temporarily unreachable.
- Change network. If broadband fails, try mobile data and vice versa; interference differs between carriers.
- Then change method. If the UDP methods (Hiddify, private network, OpenVPN) fail, switch to Cisco over TLS; if device-wide methods keep dropping, switch to the web proxy. Blocking of the three protocols is independent.
- Failing that, see the troubleshooting guide or ask in a support group with the method, region, error text and time.
FAQ
Which of the six is fastest?
On lossy networks Hiddify (hysteria2); on clean networks the difference is small and the bottleneck is region and time of day, not protocol.
Can I use several at once?
On different devices, yes — one account allows 5 devices online sharing the same allowance. On one device, never run two device-wide methods together (say, private network and Cisco); they fight over DNS and routes.
Why the recommended order private network → Cisco → OpenVPN → proxy → Hiddify?
It is ordered by how little you touch after setup: the private network logs in once and stays online, Cisco needs no import, OpenVPN imports one file, the proxy covers only the browser, and Hiddify is fastest but needs antivirus exclusions. If you already know what you want, go straight to it.
Router or client — must I choose?
No. Use the router at home and a client on the phone outside; each counts as one device.
Which for Linux?
The private network, OpenVPN and Hiddify all have Linux clients; Cisco on Linux uses the open-source OpenConnect; OpenVPN on Linux asks for credentials on the first connection. Servers and NAS are easiest with OpenVPN.
Related pages
- How we differ from other VPNs →
- What the private network (Tailscale) is →
- How to use OpenVPN and when to choose it →
- What a web proxy is and when to use one →
- Tencent Video or iQIYI Blocked Abroad? Fix It in 5 Steps →
- How to Choose a China VPN →
- Does Cisco AnyConnect Work in China? →
- Choosing a VPN Router →
- How to Import a Hiddify Subscription →
- China VPN for Students Abroad →
- Free or Paid China VPN? →
- What the Router Firmware Does →
- How to Reach Us and Never Lose Contact →
- How to Recognise a Risky VPN App →
- Which Region Is Fastest from Inside China →
- For the TV and the Grandparents at Home →
- Watching Home Cameras and a NAS in China from Abroad →
- What to Do When iOS Cannot Install an App →
- Cannot Connect, Slow, or Dropping: What to Check →
- Setting Up for Business Trips and Travel →
- On a Company Laptop: No Admin Rights, Corporate VPN Already On →
- Many Devices, One Setup, No Redo on a New Phone →
- Routing a Synology or QNAP NAS →
- Routing a Linux Server and Command-Line Tools →
- When Antivirus Flags the Client, or macOS Says It Is Damaged →
- RustDesk says the certificate cannot be verified →