PuppyIP Resource Center
Proxy Configuration Guides 12 min Published 2026-10-06

Using the VPS chain proxy script: bulk exits, link import and the management menu

With a supported VPS and authorized proxy details, follow the tutorial to install the script, paste a batch of exits and import the generated VLESS links. Use the puppyip menu afterward. Changing an exit, pausing a node and resetting its link are separate operations, and successful checks have a defined scope.

VPS Proxy chaining Proxy script Bulk exits VLESS Configuration management

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • PuppyIP serves compliant overseas businesses and authorized personnel. An overseas VPS, relay or tutorial does not change its geographic and service restrictions.
  • The current public script is 0.2.16. It supports specified Ubuntu and Debian versions and architectures, and requires root privileges and a running systemd.
  • Each batch accepts at most 50 proxy exits. Empty input creates a direct node using the VPS itself; it is not a residential proxy exit.
  • Import the complete VLESS link or QR code. Saved records differ from live checks, and server-side health does not prove every client, website or UDP path works.
  • Changing exits preserves client identity; resetting links invalidates old links. Pausing preserves settings, while changes and updates may briefly reconnect existing sessions.

What the script actually does

This guide is for people with an authorized overseas business environment who want to configure a chain proxy on their own VPS. PuppyIP Chain accepts client connections through a VLESS inbound and routes each selected node through the VPS itself or a specified socks5 exit. Each link uses one exit; it does not randomly mix all exits or turn a VPS public IP into a residential IP.

PuppyIP serves only compliant overseas businesses and their authorized personnel. Its proxy services are not offered in mainland China and must not be used there. Relaying, forwarding, sharing or reselling the service to end users in mainland China is prohibited. Overseas servers and exits do not change these restrictions, and these technical steps create no exception.

The installation and management instructions are based on the tutorial, README and 0.2.16 source read on October 6, 2026. No installation, real credential entry or line test was performed. Prerequisites and general troubleshooting remain useful separate guides; the sources retain those links. This guide focuses on installation, adding exits, importing links and managing nodes.

Step 1: check the system, permissions and materials

Prepare your VPS address, SSH port and an authorized login method. Check the operating system and existing services, then obtain usable proxy details that actually support socks5. The tutorial recommends 64-bit Ubuntu 24.04 LTS. The script supports stock Ubuntu 22.04, 24.04 and 26.04 LTS, plus Debian 12 and 13, with apt-get, dpkg and a running systemd. This does not include every Linux system or containers without systemd.

Check the architecture as well. The source recognizes x86_64/amd64, aarch64/arm64 and armv7l/armv7, selecting their corresponding Xray packages. These mappings do not guarantee installation on every ARM device; distribution, service management and permissions must also match. Installation and management require root. Other users must use their own authorized sudo privileges.

You can create an SSH connection in FinalShell as shown in the tutorial or use your preferred SSH client. Enter the VPS provider's host and SSH port, not the proxy exit port. Verify the destination and host key before opening the shell. Back up a VPS with existing workloads and arrange a maintenance window; do not reinstall its system merely to follow this tutorial.

Step 2: run installation on your own VPS

Open the PuppyIP tutorial in the sources and choose VPS configuration β†’ VPS chain proxy configuration to confirm the latest command. The current command is bash <(curl -fsSL https://raw.githubusercontent.com/feng9254/xray-chain-installer/main/install.sh). Run it in the Bash terminal of your authorized VPS, not a proxy credential field or a browser address bar.

This command downloads and executes the public main branch, so you must trust its contents at that time. Environments requiring reproducibility should review a pinned commit first. Public availability does not mean the command makes no system changes. It checks the platform, installs dependencies and deploys its own Xray service. Depending on the kernel and permissions, it may enable BBR; an unsupported BBR message alone does not prove the line is unusable.

Record the VPS entry address and TCP port printed after installation. The current default selects an available port from 62001–65534. Do not assume port 443 or put the SSH port into the client. The script does not adjust cloud security groups or the host firewall. An authorized operator must allow the final port without conflicting with existing websites or control panels.

Step 3: distinguish direct nodes from proxy exits

At the add-exit prompt, pressing Enter without input creates a direct node using the VPS public IPv4 address. Pasting proxy details creates a node for that proxy. To use a residential exit, paste the actual delivered details; generating a link from empty input does not connect a residential proxy. Empty input while editing an existing exit instead preserves that exit. Follow the specific prompt.

PuppyIP users can confirm availability under My Static IPs and copy the separated fields. Authenticated input uses IP:port:username:password; the script also accepts unauthenticated IP:port. Paste the entire batch, separated by spaces or newlines, with at most 50 exits per batch. This is a batch limit, not a total-node, speed or concurrency guarantee.

A completely fictional example is 203.0.113.10:1080:demo_user:demo_pass. The address is reserved for documentation and the credentials are dummy values, so it cannot connect. The script accepts IPv4 or a domain as the proxy host, but not an IPv6 literal. Usernames and passwords cannot contain spaces or newlines; colons in the password are retained. Do not use percent-encoded URI credentials as the raw password in separated fields.

Hidden input does not echo characters, which does not mean the paste failed. The script parses the batch, attempts to verify each exit and generates candidate configuration. The current source can still ask whether to write configuration after a failed check. Decline and investigate first; forcing a write is not successful verification. Format validation, service deployment and actual connectivity are distinct outcomes.

Step 4: import the selected node link or QR code

Installation and node creation print complete vless:// links and QR codes. Import the selected node into a client supporting its features. The README targets v2rayN with a recent Xray-core and recent Shadowrocket with VLESS and REALITY support. This does not guarantee every client or older version is compatible.

The current links use VLESS, REALITY, Vision and TCP/RAW. Several nodes may share one VPS inbound port while retaining separate identities and exits. Select the node you intend to use. REALITY does not require a separate traditional public TLS certificate, but time, SNI, public key and Short ID must match the link.

Links and QR codes contain credentials. Import them only into your own authorized clients and do not share them publicly. After importing, confirm the actual application uses the node. Successful import only means the client accepted the configuration; it does not prove the security group is open, the proxy works or the destination permits access.

Step 5: separate saved records from live checks

Run puppyip on the VPS to open management, or sudo puppyip as an authorized non-root user. Menu 2 shows lines, saved exits, links and QR codes. A saved IP is a record from creation or editing, not a current measurement. Use menu 7 or puppyip status for a live check.

The check first examines the service, inbound TCP port and Xray configuration, then observes the current IPv4 exit of enabled lines. Paused lines show not checked. An exit differing from the saved value is flagged as inconsistent; the node is not automatically replaced. Record service failures, unlistening ports and unreachable checking sites separately rather than labeling every error a bad proxy password.

A healthy result covers server-side service, configuration and TCP/IPv4 exit observations. It does not prove the client-to-VPS path, all destinations or UDP work. Ordinary UDP forwarding also depends on the proxy service and other conditions. A passed check guarantees neither account access nor platform eligibility. Perform any necessary acceptance in your actual client against an authorized test destination.

Changing exits, pausing and resetting links

Use menu 1 or puppyip add to create a line. Menu 3 or puppyip edit selects a node and changes its final exit. The current implementation preserves its VPS inbound port and client identity, so the existing link need not be imported again. Editing a remark may change the display name; that is not an identity reset. Verify the node number rather than guessing from list position.

Menu 4 pauses or enables a line while preserving identity, exit configuration and link. Re-enabling can reuse the link; pausing neither deletes configuration nor clears old passwords. Menu 6 resets the selected node identity, invalidating old links. Every device continuing to use it must import the new link. Resetting identity does not automatically change the proxy exit.

Menu 5 deletes a selected line, which cannot be restored by enabling it; the current script will not delete the final line. Prefer pausing for temporary non-use. Consider menu 10 uninstall only when the entire service is no longer needed. Deletion, reset and uninstall have separate confirmation prompts. Check y, n and the current Enter default rather than treating blank input as approval.

Updates may reconnect existing sessions

To inspect or manage existing lines, run puppyip. Running the remote installation command again may first update the management script and then enter node creation. It is not a read-only inspection command. Follow the repository and terminal for current-versus-older update conditions; ordinary management does not require uninstalling and reinstalling.

Menu 9 or puppyip update updates Xray-core, which is separate from the management script version. The repository also describes in-place management script updates and puppyip upgrade. Check existing state and backups before updating; no promise is made that every incomplete installation will repair itself.

Node changes, pause/enable operations and updates apply configuration and may restart PuppyIP's own Xray service, briefly reconnecting sessions. Preserving other node identities does not mean their existing connections are unaffected. Choose an acceptable maintenance window. Menu 0 only exits to the shell; it does not pause lines or stop the service.

Locate a failure along the actual connection path

Distinguish failed SSH login, unsupported systems, malformed batches, failed VPS-to-proxy verification, service startup failures, and client or destination failures. They occur at different stages and cannot all be solved by repeatedly generating links. Keep the time and a redacted error after a failed check, then change one condition at a time once its cause is understood.

For client-to-VPS failures, check the imported node, inbound port and actual network. For VPS-to-proxy failures, check host, port, credentials, allowlist and supported service. Then examine the destination response and permissions. Menu 7 does not replace checks of the first and final segments. The linked troubleshooting guide covers DNS, TCP, authentication, TLS and destination responses in detail.

A temporary checking-site or network failure does not prove an exit is permanently unusable. Change exits or reset identity for a specific reason. Do not rotate in bulk to evade a destination's rules, and do not record successful configuration writes as successful business acceptance.

Protect credentials and record subsequent use

Hidden input does not mean credentials are not stored. Proxy passwords enter access-restricted Xray configuration and deployment backups on the VPS. VLESS links, QR codes and backups need equal protection. Do not publicly upload configuration, logs, terminal recordings or credential-bearing diagnostic bundles. Share only times, versions, node numbers and redacted symptoms.

Record script and client versions, exit type, inbound port, check results and later changes to understand the effect of exit changes, pauses, resets and upgrades. Record downloading, copying commands, completing installation and verifying a real connection separately. This guide provides no measured success rate, speed, ranking or search volume, and chaining does not guarantee anonymity, zero logs or access to every website.

Sources

Frequently Asked Questions

Is a node created with empty input a residential proxy?

No. Empty input when adding an exit creates a direct node using the VPS public IP. Enter authorized delivery details for a residential exit. When editing an existing exit, blank input instead preserves it. Follow the current prompt.

How many exits can I add, and can I paste complete proxy URLs?

The current batch limit is 50 exits, pasted together as separated fields with spaces or newlines. This is not a complete URI input field. IPv4 and domain hosts are accepted, IPv6 literals are not, and authentication fields cannot contain spaces or newlines. The limit does not promise total capacity or performance.

Does an invisible password mean input failed?

Usually it is hidden input. Paste the batch as instructed, press Enter and inspect parsing and check results. Hidden display does not mean no storage; configuration and backups may contain passwords and must not be publicly captured or uploaded.

Must I re-import links after changing an exit?

The current script preserves the inbound port and node identity when changing the exit, so the link does not need re-importing. A remark edit may change its display name. Resetting identity is different: old links stop working and every continuing device needs the new link.

Does a healthy menu result mean my phone and every website work?

No. Menu 7 checks the server service, inbound, configuration and current TCP/IPv4 exit; menu 2 displays saved records. Verify the actual client separately. UDP, destination policies, account permissions and the local network have their own conditions.

Should I approve writing configuration after a failed exit check?

Do not treat that approval as successful verification. The current source may offer a write after the exit check fails. Decline in normal setup, check credentials, authorization, network and the checking site, resolve the problem and then continue.

Can pause, delete and uninstall replace one another?

No. Pausing preserves the node and link for re-enabling. Deletion removes the selected node and cannot be undone by enabling. Uninstall removes the service and current configuration; check historical backups separately. Applying configuration may briefly reconnect sessions, so verify the node and maintenance impact first.