Browse user guides
Advanced settings

Proxy modes, node scheduling, and configuration backups

Choose a proxy mode, node group, and multi-WAN strategy, then protect existing configuration with backups.

Difficulty
Advanced
Reading time
11 min
Verified version
V7.2.3
Updated
08/12/2026

Advanced settings change how the router handles traffic. Make one change at a time, keep a backup, and verify one test device before expanding the scope.

What you should confirm

  • The selected proxy mode matches the firmware and workload.
  • Node groups have a deliberate health and allocation policy.
  • Multi-WAN and VPN paths show the expected interfaces.
  • A recent configuration backup can be restored.

Before making changes

  1. Export a configuration backup and label it with the current version.
  2. Keep a management device outside the rules being tested.
  3. Record the current public IP and a known-good node check.
  4. Schedule changes when a short interruption is acceptable.

Understand the settings

Proxy mode controls the traffic implementation. Node scheduling controls which member a group selects. Multi-WAN controls the router's upstream path. These are separate layers; changing one does not validate the others.

1. Choose a proxy mode

Mixed compatibility

Use mixed compatibility when you need a conservative default across ordinary TCP/UDP applications. Start here when you do not yet know which applications require a specialized mode.

TUN

Use TUN when the workload needs a virtual interface path. Verify that the firmware and current traffic features support it, then test DNS, TCP, UDP, and a direct-access exception.

TProxy

Use TProxy when the workload and firmware explicitly support transparent proxying. If the control is unavailable, check the current mode, firmware capability, and authorization instead of forcing a configuration value.

2. Configure node-group scheduling

Choose health/latency preference, failover, load balancing, or average allocation based on the operational goal. Do not set a strict latency ceiling until you have observed normal latency at the target time of day.

After saving, inspect the group membership and run a diagnostic on the member selected for one test rule.

3. Configure multi-WAN distribution

Confirm the exact WAN names and link health first. Apply a small test rule, then compare the public IP from the test device. A multi-WAN policy can change the node's upstream path without changing the selected node.

4. Set node check endpoints and keepalive

Choose a check endpoint that is reachable from the expected egress. Use a stable endpoint for routine checks and avoid a single destination that may be blocked or rate-limited. Keepalive settings should follow the provider's recommendation; excessive probes can look like abnormal traffic.

For game or low-latency workloads, test the actual game or application after changing an optimization mode. A successful HTTP check is not a complete UDP validation.

5. Export and restore a backup

Export

Use the iKuai configuration backup page, wait for the file to finish, and store it offline. Record which nodes, rules, DNS options, and proxy mode it contains.

Restore

Restore only a backup from a compatible firmware and review its age first. Keep local management available through the reboot. After restoring, check service status, one node, one rule, DNS, and the public IP in that order.

  1. Backup the current configuration.
  2. Change the proxy mode and verify one test device.
  3. Adjust one node group and verify its selected member.
  4. Change multi-WAN or VPN outbound settings and verify the public IP.
  5. Add broader rules only after the small test remains stable.

Common problems

TProxy cannot be selected

Check the current firmware, plugin version, mode prerequisites, and authorization. Keep mixed compatibility while investigating.

Limits do not apply after enabling TUN

Confirm that the traffic is using the intended path and that the limit is attached to the matching rule. Test a new connection after the mode change.

A group always picks one node

Review group size, health state, scheduling strategy, and any stickiness behavior. A group with one healthy member cannot distribute traffic.

A latency threshold makes the group unusable

Relax the threshold, run diagnostics at the normal operating time, and check whether the selected endpoint is reachable from every member.

Restore succeeds but devices are offline

Check interface names, node credentials, service status, and rule targets. A backup can restore configuration values that no longer match current interfaces.

Multi-WAN changes do not change the egress

Confirm the test device matches the rule, the link is online, and the node is bound to the changed interface. Repeat with a new connection.