VPN Keeps Disconnecting? Causes, Fixes, and When to Switch

A VPN that connects successfully and later drops has a different problem from a VPN that never connects. Record exactly when the tunnel fails: after sleep, when switching from Wi-Fi to mobile data, during heavy upload, on one server, or at a regular interval. Then enable the provider's documented auto-reconnect, verify what the kill switch does after a drop, and compare another nearby server and protocol.

If the problem occurs only on one Wi-Fi network, investigate signal quality, roaming, router firmware, ISP routing, or session timeouts. If it occurs only on a phone after the screen turns off, battery optimization or background restrictions are likely. If it repeats across servers, networks, and updated devices, the provider's app or network may not be stable enough for your use and a switch is reasonable.

Last verified: 2026-08-05

Diagnose by the moment of the drop

Drop pattern Likely cause First action
After screen locks or device sleeps Battery optimization, background suspension, sleep networking Allow documented background operation; test with screen awake
Moving between Wi-Fi and cellular Network change invalidates tunnel Enable auto-reconnect; test provider's mobile-friendly protocol
Only on one server Server maintenance, route, or load Use another server in the same region
Only on one Wi-Fi network Weak signal, roaming, router/NAT, ISP filter Test Ethernet/mobile data and restart/update router
At a regular interval NAT/session timeout, DHCP renewal, scheduled router event Note interval; inspect router logs and reconnect settings
During heavy download/upload Packet loss, MTU, router CPU, unstable path Test lower load, another protocol, native app
VPN drops and internet remains blocked Kill switch works but reconnect failed Reconnect in app; inspect auto-reconnect and server status

If the tunnel never establishes, go to VPN not connecting. If you have not yet isolated the symptom, start with the umbrella VPN not working guide. If the main problem is throughput rather than drops, use VPN too slow.

Server and network route

Start with a different server in the same country. A single server can be under maintenance or have a poor route to your ISP. If the alternative remains stable, keep it and report the original endpoint with the time and protocol.

If several nearby servers drop but a distant one does not, the regional route may be the issue. If all servers drop only on one ISP or Wi-Fi network, the provider may be fine and the local path is unstable or filtering traffic.

Use continuous pings only as supporting evidence. Many servers and networks deprioritize ICMP, so missed ping replies do not always mean the tunnel dropped. More useful evidence includes the VPN app's state, public IP change, system log, and whether an active HTTPS or call session failed.

Server load can contribute to poor performance, but a high load indicator is not proof of disconnections. Compare at least two server numbers and record the pattern.

Wi-Fi, mobile data, and network switching

A mobile device moving between access points or from Wi-Fi to cellular obtains a new local IP and route. The existing VPN tunnel may not survive. A well-designed app should reconnect, but there can be a brief interruption.

Test these separately:

  1. remain on one strong Wi-Fi network for 20–30 minutes;
  2. remain on cellular for the same period;
  3. deliberately move from Wi-Fi to cellular;
  4. return to Wi-Fi;
  5. note whether the app reconnects and whether the kill switch blocks traffic during transition.

Weak Wi-Fi can look like a VPN failure. Compare the non-VPN connection for packet loss and calls. Restart the router, update firmware, and test 5 GHz/Ethernet. Do not reduce Wi-Fi security or disable the firewall.

Private or randomized Wi-Fi addresses can cause a captive portal or hotel network to treat a device as new after settings change. Complete the portal before reconnecting the VPN.

Sleep mode, battery optimization, and background limits

Mobile operating systems restrict background apps to save power. A VPN normally uses a privileged network service, but vendor-specific battery managers can still suspend or terminate it.

On Android, use the provider's device-specific instructions to exempt the VPN from aggressive battery optimization if necessary. Do not grant unrelated permissions. On iOS and iPadOS, update the app and OS, and verify that the VPN configuration remains present. On laptops, test whether the drop happens only after sleep or lid close.

For a headless Linux system, confirm the systemd service is enabled and configured to restart. A desktop app configured only to launch after graphical login may not reconnect after reboot.

A connection that fails after every restart may be an auto-start problem rather than network instability. Test manual connection immediately after boot.

Auto-reconnect, kill switch, and no internet after a drop

Auto-reconnect attempts to establish a new tunnel. A kill switch blocks traffic when the tunnel is absent. These functions complement each other but can create the appearance that “the internet died” when reconnect fails.

Verify three scenarios:

  • manually disconnect through the app;
  • terminate the network by turning Wi-Fi off and on;
  • connect to an unavailable server or briefly interrupt the router.

Observe whether ordinary traffic is blocked, whether the app selects another server, and whether manual intervention is required. Settings can differ by platform. Surfshark, for example, documents auto-connect and kill-switch controls in its apps, while other providers separate an ordinary kill switch from an advanced always-on or lockdown mode.[1]

Do not force-stop the VPN process while strict kill switch is active and then assume the network is broken. Open the app, reconnect or disable the mode through its documented control.

Protocol, MTU, and router behavior

Different protocols react differently to changing networks and packet loss. WireGuard usually reconnects efficiently, while IKEv2 has traditionally been useful for mobile transitions. Provider implementations and OS support matter more than the protocol label alone.

Try automatic/smart mode first, then a modern UDP protocol, then a provider-supported TCP fallback if the route is unstable or filtered. TCP may be slower, but can be more usable on some restrictive networks.

MTU problems can cause stalls or apparent drops under load. Treat MTU as an advanced step after server, network, protocol, and app checks. Use vendor guidance and save the original value.

Routers can drop tunnels because of:

  • CPU or memory exhaustion;
  • stale keys or certificates;
  • WAN reconnects and DHCP renewal;
  • NAT/session timeout;
  • firmware bugs;
  • health checks that restart the interface;
  • incorrect keepalive values;
  • multiple policies competing for the same route.

Compare a native app on a wired computer. If it remains stable, the router configuration or hardware is the likely limit. The best VPN for routers guide explains compatibility criteria.

A step-by-step repair plan

  1. Update the VPN app, operating system, and router firmware.
  2. Record the drop time, server, protocol, network, and trigger.
  3. Test another server in the same region.
  4. Test the provider's automatic or modern default protocol.
  5. Enable documented auto-reconnect.
  6. Verify kill-switch behavior during an intentional network interruption.
  7. Test one stable network without roaming.
  8. Test another network or mobile data.
  9. Remove battery restrictions only for the official VPN app.
  10. Test with optional multi-hop, obfuscation, and split tunneling disabled.
  11. Compare native app against router configuration.
  12. Export sanitized logs and contact support.

Change one setting at a time. Otherwise, a temporary improvement will not reveal which change mattered.

How to evaluate another VPN for stability

Do not rank stability by a single speed test. During the refund period, run a repeatable endurance check:

  • connect to the nearest server for several hours;
  • sleep and wake the device;
  • switch Wi-Fi access points;
  • move between Wi-Fi and mobile data;
  • perform a video call or long download;
  • restart the device and verify auto-start;
  • deliberately interrupt the network and inspect kill-switch/reconnect behavior;
  • repeat at the time when the old provider usually failed.

Record the number, duration, and recovery of drops. A brief reconnection during a network change is different from an unexplained tunnel loss on a stable wired connection.

When to switch providers

Switch when:

  • drops occur across multiple nearby servers and protocols;
  • the problem repeats on two networks and devices;
  • support cannot interpret logs or provide a stable build;
  • the app lacks reliable auto-reconnect on your platform;
  • the kill switch frequently leaves the system unusable without clear recovery;
  • required router configurations need manual intervention every day;
  • updates repeatedly reintroduce the same defect;
  • the provider's server coverage forces unstable distant routes.

A replacement should have official apps for your devices, current protocol options, documented reconnect controls, usable nearby servers, and a refund policy. Use the best VPN guide to compare those properties.

FAQ

Why does my VPN disconnect when my phone screen turns off?

Battery optimization or background restrictions may suspend the app. Update it and apply only the provider's documented battery exception.

Why does the VPN drop when I leave Wi-Fi?

The device changes local IP address and route when moving to cellular. Enable auto-reconnect and test a protocol that the provider supports for mobile transitions.

Why is there no internet after the VPN disconnects?

The kill switch may be blocking fallback traffic as designed while auto-reconnect has failed. Reopen the app and reconnect or use its documented disconnect control.

Should I disable the kill switch to stop drops?

No. It does not usually cause the underlying tunnel loss. Disable it only briefly for diagnosis on a trusted network and re-enable it afterward.

Can MTU cause regular disconnections?

It can contribute to stalls or failures under certain paths, but regular intervals more often point to session timeouts, network renewal, or scheduled router behavior. Tune MTU only with documentation.

Is WireGuard always the most stable protocol?

No. It is efficient and often reconnects well, but filtering, routing, app implementation, and the operating system can make another supported protocol more stable.

When are repeated drops enough reason to change VPNs?

When they persist across servers, protocols, devices, and networks and support cannot provide a reliable fix or compatible client.

Sources


  1. Surfshark: Auto-connect ↩︎