The Complete Beginner's Guide
From how a 机场 differs from a VPN, to protocols and line types, to picking a client and importing a subscription link, to choosing a service and handling a shutdown — laid out in the order a first-time user actually runs into these questions. Read it top to bottom, or jump straight to what you need.
What’s a 机场, and how is it different from a VPN?
The first time you run into the term “机场” (literally “airport” — slang for a paid proxy-subscription service), the vocabulary alone can be confusing. It has nothing to do with actual airports; it’s just slang specific to this corner of the internet.
“Circumvention” (getting around network blocking) is the goal, not a specific method. “梯子” (“ladder”) is the general term for any circumvention tool. A “机场” is one kind of ladder, specifically: a subscription-based proxy-node service. The provider runs nodes overseas, you subscribe monthly or annually, get a subscription link, and import it into a client app to actually use it.
Where does a VPN fit in? A VPN (virtual private network) is a different encrypted-tunnel technology. The one-tap commercial VPN apps you’ve probably seen work on a similar principle, just implemented differently from a proxy-subscription service. The real difference isn’t “does it work” — it’s the experience and the setup cost:
- A proxy-subscription service (机场): usually cheaper and faster, but you pick your own client (Clash, Shadowrocket, etc.) and import the subscription link yourself — you need to understand a bit about nodes and protocols.
- A commercial VPN: download the app, log in, tap connect — almost no configuration involved, but it’s usually pricier, and speed and censorship-resistance aren’t necessarily better than a proxy service.
Put simply: a proxy service sells you “nodes” and leaves “how to use them” up to you; a VPN sells you the whole experience, setup included. That’s why a proxy service takes a bit more effort to get started with — but once you understand how the subscription link and client fit together, it stays low-maintenance from there.
You need two things: a subscription + a client
Using a proxy service always comes down to two steps:
- A subscription: after signing up and buying a plan, you get a subscription link (a growing number of providers now require you to contact support for it instead of handing it over automatically — the reason why, and how to handle it, is covered in the Clients & Setup section below).
- Client software: import the subscription link into a client to see and connect to the node list. The common client per platform is covered next.
Once these two pieces click, picking a protocol, a line type, and eventually a provider gets a lot easier to reason about.
Protocols, and what line type actually means
Protocols first, since it’s the quicker topic: the common ones are Shadowsocks, V2Ray, Trojan, and Hysteria2, and day-to-day experience doesn’t differ all that much between them — Shadowsocks is the simplest and needs no certificate; Trojan disguises its traffic as HTTPS for better stealth; Hysteria2 runs on QUIC/HTTP3 and shows a bit more of a speed edge when the underlying line quality is mediocre. Unless you have a specific reason not to, just use whatever protocol the provider gives you by default.
Line type is what actually drives price and experience, and it’s the concept newcomers get tripped up on most, so it’s worth spending more space on.
Three line types, three ways of getting past the wall
Break the path your data takes from your home to an overseas website into three legs: your home connection to a domestic entry point, that entry point to the overseas node (this is the leg that determines line type), and the overseas node to the actual destination site. That middle leg splits into three common approaches:
- Direct: the client connects straight to an overseas server, no domestic relay in between — traffic crosses the firewall directly. It’s the simplest architecture and the cheapest: a provider only needs a few overseas cloud servers (AWS, Vultr, etc.) to start selling, which is how prices get pushed down to just a few dollars a month. The tradeoff is just as direct — node IPs sit out in the open, get identified and blocked more easily, and peak-hour performance swings more.
- Transit (BGP): adds a domestic relay plus an encrypted tunnel on top of the direct approach, then connects out through an overseas exit. This is the architecture behind most of the “BGP transit” services in this comparison — better peak-hour stability than direct, though the traffic is still technically crossing the firewall, just with more encryption and hops making it harder to fingerprint.
- Dedicated (IPLC / IEPL): fundamentally different from the other two. IPLC/IEPL is a physical-level private circuit leased between carriers — essentially a telecom operator’s own leased fiber connecting two cities directly. It doesn’t touch the public internet or cross the firewall at all — that’s the actual reason it costs more, not just a marketing label. Because it skips the public internet entirely, latency is lower and it’s more resistant to interference, which is why it suits latency-sensitive use like gaming or video calls.
Roughly by price: direct is cheapest, usually a few dollars up to around ten a month; transit comes next, and it’s what most of this comparison’s “budget” and “best value” services actually run on; dedicated costs the most — though not always by a huge margin. A couple of services in this comparison (Wuyou, Firefly) price their entry-level IPLC plans around $1-1.10/month, cheaper than some pure-transit competitors — so “dedicated always costs more” isn’t a hard rule, it comes down to each provider’s own pricing.
If you want to verify a provider’s line-type claim yourself
Most people don’t need to go this deep — what a provider states on its own site is usually a fine enough reference point. But if you want to check it yourself, a couple of advanced options exist: run a traceroute and look at the hop count — a genuine dedicated line typically shows just 3-5 hops with almost no public backbone nodes in between; or look up the entry IP’s ownership (a tool like IP.SB works) — BGP transit commonly shows cloud-provider IPs (Alibaba Cloud, Tencent Cloud), while dedicated lines tend to show carrier-owned address blocks instead. This gets technical fast — dig in if it interests you, skip it if it doesn’t; it won’t affect your ability to pick a service either way.
Picking a client, and how to import a subscription link
Once you have a subscription link, you still need a client to actually use it. Most mainstream clients today are built on the Clash core (or a compatible one) — the exact app differs by platform, covered below.
Windows / macOS: Clash Verge Rev
For Windows and Mac, Clash Verge Rev is a solid pick right now — clean interface, the usual rule/subscription-update/routing features you’d want, and it’s open source with fairly active updates. Get it from its GitHub Releases page: open the latest release and pick the file for your system — on Windows that’s usually the one ending in x64-setup.exe (or arm64-setup.exe on an ARM-based PC); on Mac it depends on your chip — Apple Silicon (M-series, 2020 or later) wants aarch64.dmg, Intel Macs want x64.dmg. Not sure which chip you have? Apple menu → About This Mac tells you. After installing, paste the subscription link your provider gave you into the subscription page, and the node list pulls in automatically.
Official download: Clash Verge Rev GitHub Releases
Android: FlClash
On Android, FlClash is the recommendation — also a Clash-core-based open-source client, with an interface and workflow that feels close to the desktop Clash apps, so it’s an easy jump if you’ve used one already. Get it from its GitHub Releases page: the file with arm64-v8a in the name is the right pick for the vast majority of Android phones made since roughly 2018; only older devices need armeabi-v7a — if you’re unsure, try arm64-v8a first. Import works the same way: copy the subscription link, add a new subscription in the app, paste it in.
Official download: FlClash GitHub Releases
iOS: Clash Mi, Nextin
For iOS, Clash Mi and Nextin are both worth a look. Unlike Windows or Android, iOS won’t let you install an app straight from a website without jailbreaking, so both of these are App Store installs, not something you’d grab from GitHub — if you come across a link claiming to offer a direct “Clash Mi installer” outside the App Store, treat it as suspicious; that’s not the official channel. If you’ve already been using Shadowrocket, there’s no need to switch — just know it requires a non-mainland-China Apple ID to download, which is an extra hurdle for some people; Clash Mi and Nextin tend to be friendlier on that front.
Regardless of which client you land on, importing a subscription link follows roughly the same steps everywhere: copy the link your provider gave you, find the “subscription” or “profile” section in the client, paste it in, and the node list pulls in automatically. Exact button placement varies by app and shifts with updates, so treat this as the general idea rather than an exact walkthrough — we can’t track every app’s UI changes in real time.
One exception worth flagging: not every provider runs on the “Clash + subscription link” model. Some build their own dedicated app instead — log in with an account and password and you’re set, no subscription link and no separate Clash-style client needed. Routing rules (what goes through the proxy, what connects directly) get configured inside that app too, rather than through an imported subscription profile. Which model a given provider uses is something to check on their site or with support.
Official download: Clash Mi (App Store) · Nextin (App Store) (Clash Mi is open source — its project page is here)
Why some providers make you ask support for the link
Over the last couple of years, a growing number of providers have stopped posting the subscription link directly on your plan page — you sign up, then have to contact support to get it, or the provider replaces it with their own app entirely. The first time this happens, it’s easy to assume the provider’s being deliberately difficult. Usually that’s not it.
Here’s the plain version: once a subscription link is out in the open, it’s effectively exposing the node addresses behind it. A link that gets resold, screenshotted into a group chat, or just picked up by someone who bought a plan can be used to hit it repeatedly, pull the node domains out, and probe them until a pattern shows up — once that pattern gets flagged, the nodes tend to get blocked as a group, not because you did anything wrong, just because the link became a key pointing straight at the provider’s infrastructure. gfw.report, an independent research group focused on GFW detection techniques, has published more detailed technical writeups on this if you want to go deeper — worth a search if you’re curious.
The common fix comes in two flavors: some providers still hand out a link, just gated behind support and effectively one-time-use — among the services covered on this site, Firefly, Weifeng, Shanyue, Lingmao, and Kuajieyun all work this way. Others go further and drop the generic subscription link entirely in favor of their own app — Wuyou does this: log in with an account and password, and even routing rules get configured inside the app rather than through a subscription YAML that Clash would read.
If you’re on Windows, seeing Defender pop up “Windows protected your PC” or an “unknown publisher” warning when installing one of these provider-built apps is common — smaller tools usually haven’t paid for a code-signing certificate, so Windows doesn’t recognize the publisher. That doesn’t necessarily mean anything’s wrong, but it’s also not something to just click through without a second thought. The safer move: download it, don’t open it yet, and run the installer through Jotti’s malware scan first, which checks it against multiple antivirus engines. If you already have a working way online, VirusTotal works too — it’s Google-owned, so it’s blocked without circumvention already in place, meaning you’d need one working connection just to check another. If nothing flags it, go ahead and install.
Worth being honest about: neither approach eliminates the risk, just lowers it — even with a dedicated app, anyone willing to capture its actual network traffic can still extract which node domain it connects to. But putting in the effort to lock this down is itself a decent signal — at minimum, it suggests the provider takes node uptime seriously rather than leaving it on autopilot.
If you sign up and can’t find a subscription link, don’t assume something’s wrong — just message support, that’s normal now. If support goes quiet for an extended stretch instead, that actually is a warning sign, the same category covered in if a service shuts down below. And one thing worth keeping in mind either way: forwarding your own subscription link into a group chat or to a friend recreates the exact exposure problem this whole practice exists to prevent — better to just keep it to yourself.
How to pick a service you can actually trust
This market is a mixed bag — prices range from a few dollars to well over a hundred a month, and service quality and shutdown risk vary just as widely. Line type — direct vs. transit vs. dedicated — is covered above; here’s what else is worth checking.
Do some free digging before you pay
Most providers let you register an account for free, no need to fund it first — that free window is actually a good chance to vet whether a provider is legit, and it only takes about ten minutes. A few things worth checking once you’re in:
- When was the last announcement posted? Look for a “notices” or “announcements” section in the dashboard, and see when the most recent one went up. Frequent updates suggest an active, functioning team; if the latest post is from six months ago or more, that’s worth noting.
- How complete are the setup guides? Is there a real walkthrough for Clash, Shadowrocket, and other common clients, and how detailed is it? A provider that bothers writing this out in full usually isn’t the type to launch and walk away.
- Actually message support with a real question. Find the live chat or ticket system and ask something concrete — “how many nodes do you currently have,” or “what line type does the [region] node use.” Whether the answer itself is accurate matters less than two things: whether they respond at all, and how long it takes. Going quiet for half a day, or dodging the question, tells you more than any marketing page will.
None of this costs anything — registering is free. Ten minutes here beats swiping a card on an annual plan sight unseen.
Start monthly, be cautious with annual plans
If it’s your first time with a given provider, start with a monthly plan for 1-2 months and actually test the speed, stability, and support responsiveness before considering an annual plan for the discount. The annual discount comes with a trade-off: prepayment risk. If a provider shuts down mid-year, unused prepaid balance is usually very hard to recover.
Warning signs a service might be about to shut down
- A sudden, deeply-discounted annual or multi-year promotion, far below the normal price
- Support goes silent for an extended period, or their community channel gets locked to admin-only posting
- A large number of nodes fail for days with no official explanation
- Existing customers get ignored while the provider keeps aggressively marketing for new sign-ups
No single signal necessarily means trouble, but multiple signals at once are worth taking seriously. For a fuller response plan, see the section below.
Keep a backup
No provider can guarantee it’ll never have problems. The safer approach is to keep 1-2 backup services in reserve rather than putting all your prepaid budget into one provider.
Want to jump straight to the data? Head to the full comparison table on the homepage, or browse by need: Best Value, Most Stable, and the other category pages.
If a service shuts down
If a provider you use has just shut down, or you’re worried one might, here’s a practical set of steps.
Step one: stop auto-renewal
Immediately check for and cancel any auto-renewal/auto-billing tied to that provider’s account, so you don’t keep getting charged.
Watch out for fake “compensation” or “refund” messages
After a shutdown, it’s common to see DMs or links claiming to be “official compensation” or a “migration to our new site.” Many of these are phishing scams designed to steal your payment details or squeeze one more charge out of you. Don’t click unfamiliar links, and don’t hand over payment or account information in response to messages like this.
The realistic odds of getting your money back
Honestly, once a provider in this kind of unregulated market decides to shut down and disappear, recovering prepaid funds through any formal channel is very unlikely — there’s no contract, no support ticket system backing you up. This is the core reason to favor monthly billing and be cautious with annual commitments.
Turn this into a reason to diversify
Relying on a single provider is putting all your eggs in one basket. After a shutdown, the practical moves are:
- Run 1-2 services at once — a primary and a backup — instead of depending on just one
- Favor providers that have been operating longer with a relatively stable reputation
- Before paying for anything substantial, search the provider’s name plus “shut down” or “reviews” to check for recent real feedback
If you need to pick a new provider, see how to pick a service above, or go straight to the full comparison table on the homepage.
Sources: background on line-type architecture and identification methods in the "Protocols & Lines" section draws on publicly available technical writeups from eoht.net.