Guide

A VLESS Tunnel to Your Chicago Mobile Proxy

Most customers connect to a Chicago Proxies line with a plain HTTP(S) or SOCKS5 login and never need anything else. Some do: people on networks that interfere with proxy ports, people who want every app on a phone to use the line without per-app settings, and people who prefer an encrypted tunnel end to end. For them a line can be used through a VLESS tunnel, which is the protocol spoken by Xray and the clients built on it. This guide explains what VLESS is, when to use it instead of the plain logins, and how to set it up on each platform, with placeholders where your own values go.

What VLESS is

VLESS is a lightweight transport protocol used by the Xray family of software. A client on your computer or phone opens one encrypted connection to a server, and everything you send through that connection comes out the far end as if it came from the server. In our case the far end is your Chicago line: traffic enters the tunnel on your device and leaves the carrier network in Chicago on your line's address.

Compared with HTTP or SOCKS5, VLESS carries any kind of traffic, TCP and UDP, without the application needing to know about proxies at all. The client presents itself to your operating system as a local proxy or as a VPN-style interface, and the apps simply use it. The identity is a UUID instead of a username and password, and the connection is typically wrapped in TLS so it looks like ordinary HTTPS to anything in between.

When to use it over HTTP or SOCKS5

If you are setting a proxy in a browser profile, a scraper or a single app, the plain login is simpler and there is no reason to change. VLESS earns its place in a few situations.

  • You are on a network, hotel or office or country, that blocks or interferes with proxy ports; a TLS tunnel on a normal port passes where a raw SOCKS5 connection does not.
  • You want a whole phone to use the line: every app, not only the browser, with no per-app proxy support needed.
  • You need UDP for an app that does not speak SOCKS5.
  • You want the hop between you and our rack encrypted end to end rather than relying on each app's own TLS.
  • You use a client that only speaks VLESS and would rather not add another tool.

What you need from the dashboard

Open your line in the dashboard at https://chi.chicagoproxies.com. If VLESS is enabled on the line, you will see a VLESS link and the values it is built from: the server host, the port, your UUID, the security setting and any transport options. Copy the link as it is; the client reads all of it. The link looks like the sample below, with your own values in place of the placeholders.

vless://<uuid>@<host>:<port>?encryption=none&security=tls&type=tcp#Chicago-line

Windows and Mac

The desktop clients all accept the link directly; there is nothing to type by hand.

  1. Install an Xray-based client. On Windows, v2rayN is the common choice; on Mac, V2rayU or Hiddify.
  2. Open the client and choose to add a server from the clipboard or from a link, then paste the VLESS link from your dashboard.
  3. Check that the imported entry shows the host, port, UUID and TLS setting that match the dashboard.
  4. Set the client to system proxy mode so every app uses it, or leave it as a local proxy on 127.0.0.1 and point individual apps at it.
  5. Connect, then open an IP lookup page; it should show the carrier and Chicago or Illinois.

Android and iOS

On a phone the client installs as a VPN profile, which is how it captures every app without per-app settings.

  1. On Android install v2rayNG or Hiddify; on iOS install Shadowrocket, Streisand or V2Box.
  2. Import the VLESS link by pasting it or by scanning the QR code shown in your dashboard, if your line's page shows one.
  3. On iOS the app will ask to add a VPN configuration; allow it, because that is how it captures all apps' traffic.
  4. Enable per-app routing if you want only some apps on the line; the default is everything.
  5. Connect and verify with an IP lookup page in a browser and, if you can, in one of the apps you care about.

A config snippet for your own Xray

If you run Xray yourself, for example on a Linux machine that then exposes a local SOCKS5 port to your tools, the outbound looks like this. Replace the placeholders with the values from your dashboard and keep the rest.

{
  "outbounds": [
    {
      "protocol": "vless",
      "settings": {
        "vnext": [
          {
            "address": "<host>",
            "port": <port>,
            "users": [
              { "id": "<uuid>", "encryption": "none" }
            ]
          }
        ]
      },
      "streamSettings": {
        "network": "tcp",
        "security": "tls",
        "tlsSettings": { "serverName": "<host>" }
      }
    }
  ]
}

Checks and common problems

After connecting, confirm three things: the address on an IP lookup page belongs to the carrier and reads Chicago or Illinois; a UDP-based app works if you needed UDP; and your real address does not leak on a WebRTC test. If the client connects but pages do not load, the usual causes are a mistyped UUID, a wrong port, or a client with TLS turned off while the link says security=tls.

Rotation works the same through the tunnel: use the dashboard, the rotation link or a timer, and the tunnel stays up while the carrier address changes. If the tunnel itself drops after a rotation, reconnect the client; that is normal for some clients.

  • Client connects, nothing loads: re-import the link from the dashboard rather than editing by hand.
  • Works on Wi-Fi, fails on cellular: your own carrier may be blocking the port; try the alternative port if your dashboard shows one, or ask support.
  • Address shows your home ISP: the client is not in system or VPN mode, or the browser bypasses the proxy; check the client's routing.
  • Slow: the line's speed is 20–45 Mbps on 4G and 50+ Mbps on 5G; a slow result usually means your own uplink or a congested cell, and support can check the line.

Frequently asked

Is VLESS more private than SOCKS5?

The hop between your device and our rack is encrypted inside the tunnel, which SOCKS5 on its own is not. From the website's side nothing changes: it sees the same Chicago carrier address.

Can I use VLESS and the HTTP login at the same time?

Yes. They are two doors to the same line and the same address. Use whichever each tool prefers.

Does VLESS cost extra?

No. It is part of the line, from $2 for 2 hours or $5/day.

Which client do you support?

Any Xray-compatible client should work with the link. We test with the ones named above; if yours misbehaves, write to [email protected] or @ChicagoProxiesBot with the client name and version.

USA mobile proxies on hardware we own

Real 4G and 5G carrier IPs in eight US metros, with unlimited rotation, sticky sessions and HTTP(S) or SOCKS5. Try a line by the hour from $2 for the first two hours, or take a full day from $5; the hours you paid count toward the day.

View plans See all locations

More guides

All Chicago Proxies resources →