VPN Won’t Connect? Causes, Fixes, and When to Switch
When a VPN will not connect, first verify that the internet works without it, the subscription and login are valid, and the provider is not reporting an outage. Then try another server and another supported protocol. If the VPN works on mobile data but not on Wi-Fi, the network or router is probably interfering. If it fails on every network but only on one device, the app, virtual adapter, operating system, firewall, or security software is the more likely cause.
Do not repeatedly reinstall the client or disable the firewall permanently. Record the exact error, server, protocol, device, network, and time. Complete any hotel or airport captive portal before starting the VPN. In restricted networks, use only the provider's documented TCP or obfuscation mode. If no supported protocol works across several devices and networks, or the provider lacks a compatible app for your platform, changing providers is justified.
Last verified: 2026-08-05
Quick checks before changing settings
| Check | Pass result | What failure suggests |
|---|---|---|
| Internet works with VPN off | Ordinary sites load | ISP, Wi-Fi, or device network issue if not |
| Provider account login works | Subscription active and credentials accepted | Expiry, billing, password, or account lock |
| Another server connects | Tunnel establishes elsewhere | Individual server maintenance or route issue |
| Another protocol connects | Connection succeeds | Current protocol/port is blocked or unstable |
| Mobile data works, Wi-Fi fails | Same device connects on cellular | Router, captive portal, ISP, school, hotel, or office filter |
| Other device works on same Wi-Fi | Second device connects | Local app, OS, adapter, or security conflict |
| All devices/networks fail | No supported path works | Provider outage, account, regional blocking, or broad incompatibility |
This page is about failure to establish the tunnel. If it connects and later drops, use VPN keeps disconnecting. For a broader symptom map, see VPN not working.
Internet, subscription, login, and service status
Start outside the VPN. Disconnect it using the app's normal control and open two unrelated HTTPS websites. If ordinary internet is down, fix Wi-Fi, Ethernet, mobile data, or the ISP first. A VPN cannot establish through a connection that has no usable route.
Next, sign in to the provider's official account page. Confirm:
- the plan has not expired;
- the device or connection allowance is not exceeded;
- the password and multifactor method work;
- the account is not suspended;
- the provider has not changed its app or plan requirements.
A failed app login and a failed VPN handshake are different. Do not reset the password unless the account login actually fails. Check the provider's official status page or support channel for maintenance. A single unavailable server is normal operational maintenance; select another server rather than reinstalling.
Automatic date and time must be correct. TLS certificates and authentication tokens can fail when the clock is wrong. Proton's official troubleshooting guide specifically lists incorrect system time, expired plans, unavailable servers, firewalls, and lack of internet as common causes.[1]
Server, protocol, and port
VPN protocols use different transport behavior. A network may allow one and block another. Try in this order:
- the provider's automatic or smart protocol;
- WireGuard or the provider's modern default;
- another UDP option;
- a provider-supported TCP mode;
- the provider's official obfuscation or stealth mode when the network is restrictive.
Do not enter random ports or use undocumented configuration files. A manual OpenVPN or WireGuard profile can be useful on routers and Linux, but only if generated from the provider's account and kept current.
Try a different server number in the same country, then a nearby country if location is not essential. If one server fails, it may be offline. If an entire region fails, routing or blocking may be involved. If only the required country fails, contact support before assuming the whole service is unusable.
Obfuscation is not guaranteed access. NordVPN documents obfuscated servers and NordWhisper; Proton documents Stealth. Availability differs by device. Confirm that the mode exists on the exact platform before subscribing for travel.[2][1:1][3][4]
Firewall, antivirus, and network filters
A firewall can block the VPN executable, service, driver, or outbound port. Security suites may also inspect HTTPS, filter DNS, or install their own network extension. Use a controlled test:
- update the VPN and security product;
- verify the VPN publisher and executable path;
- add a documented allow rule if the provider instructs it;
- briefly pause only the relevant module if necessary to isolate the cause;
- reconnect;
- restore protection immediately;
- contact the security vendor if the conflict is confirmed.
Do not leave the firewall disabled, turn off certificate validation, or create broad “allow all” rules. On managed work or school devices, you may not be authorized to change security settings.
Apple advises checking VPN and third-party security software when network connectivity is affected and testing another network. Windows can also have stale virtual adapters or network filters, but a full network reset is a late step because it removes configurations and may require VPN and virtual-machine software to be reinstalled.[5][6]
Captive portals and restricted networks
Hotel, airport, cafe, and transport Wi-Fi often requires a web login before normal access. Join the network with the VPN disconnected, open the captive portal, accept the terms or enter the authorized credentials, confirm an ordinary site loads, and then connect the VPN.
If the portal will not appear, forget and rejoin the network or use the venue's official instructions. Do not enter credentials into a page with an unexpected domain or certificate warning. A travel router may need its own captive-portal process.
Schools, offices, libraries, and public Wi-Fi can deliberately block VPN protocols. A TCP or obfuscated mode may work, but bypassing an organization's policy can violate its rules. Use mobile data or request authorized access where appropriate.
Countries with internet restrictions can block provider sites, server IPs, and protocol signatures. Install and test apps before travel, keep official configurations offline, and review the current VPN for China guide when that is the destination. No availability claim should be treated as permanent.
Device-specific checks
Windows
Update Windows and the official VPN app. Confirm the app's background service is running and the virtual adapter appears without an error. Remove old VPN clients only if they are no longer needed; competing filter drivers can conflict. Use network reset only after saving configurations and trying another network.[6:1]
macOS and iOS
Approve the provider's network extension or VPN configuration when prompted. Check Settings for multiple VPN and device-management profiles. Restart after an app update if the extension does not load. Do not remove an employer-managed profile.
Linux
Confirm the distribution and architecture are officially supported. Check the service status, logs, NetworkManager/systemd state, DNS resolver, and whether an old manual tunnel is already active. Use the best VPN for Linux guide when platform support is the underlying problem.
Android and Fire TV
Disable aggressive battery optimization for the VPN only if the provider documents it. Update Google Play/Amazon Appstore builds and verify the device's OS version. On Fire TV, use the official television app rather than an unknown phone APK.
Routers
Confirm internet works through the router without the VPN profile. Check certificates, credentials, system time, DNS, firmware, and the provider's configuration format. A consumer provider app cannot be installed on most routers; you need supported manual files or firmware. See best VPN for routers.
Reading logs and common error classes
Logs should be collected from the official app without publishing account tokens, keys, or full configuration files. Error wording varies, but common classes include:
| Error class | Meaning | Action |
|---|---|---|
| Authentication failed | Credentials, token, certificate, or plan issue | Sign in to account; regenerate official config |
| Timeout / server unreachable | Route, firewall, blocked protocol, or offline server | Change server/protocol/network |
| TLS/certificate error | Wrong time, interception, stale config, or server issue | Correct clock; update app/config; do not bypass validation |
| Adapter/permission error | Driver, extension, OS permission, or conflicting client | Approve extension; repair official app; inspect other VPNs |
| No server available | Maintenance, plan/location restriction, or outage | Choose another server; check status and plan |
| DNS error after connection | Tunnel established but resolver/routing failed | Use connected-without-internet branch, not this page |
Send support the smallest useful set: time zone, app version, OS, server, protocol, network type, exact error, and sanitized logs.
When to reinstall
Reinstall when the official client is corrupted, a virtual adapter or network extension did not install, an update was interrupted, or support requests a clean installation. Before removing it:
- save manual configurations and custom rules;
- export logs;
- record kill-switch and split-tunnel settings;
- confirm you can obtain the installer from the official source;
- disable always-on mode through the app;
- restart after uninstalling before reinstalling.
Reinstallation will not fix provider IP blocking, a restricted country, an expired plan, an unsupported device, or a network that forbids VPNs.
When to switch VPN providers
Change providers when the failure is persistent and structural:
- no supported protocol connects on the networks you regularly use;
- the required obfuscation mode is absent on your device;
- the provider no longer supports your OS, architecture, or router;
- multiple servers fail across two devices and two networks while another VPN works;
- support cannot identify an outage or provide a compatible configuration;
- recurring regional blocking makes the service unusable for travel;
- app updates repeatedly break the connection without a stable fallback.
Test a replacement on the same network and device before committing. A service with several protocols, official apps, manual configurations, and responsive support is more valuable than a larger marketing server count.
FAQ
Why does my VPN connect on mobile data but not Wi-Fi?
The Wi-Fi network, router, captive portal, ISP, or organizational filter is likely blocking the current protocol or server. Complete the portal and try an official TCP or obfuscation mode.
Should I change the VPN port manually?
Only when the provider documents the port and configuration. Random ports can fail or weaken the setup.
Can an incorrect clock stop a VPN connection?
Yes. Authentication and certificates depend on accurate time. Enable automatic date, time, and time zone, then retry.
Is disabling antivirus a safe fix?
Not as a permanent fix. Use a brief controlled test, restore protection, and create only a documented narrow exception if the conflict is confirmed.
Why can no server connect in one country?
The provider's server IPs or protocols may be blocked, routing may be disrupted, or the provider may have an outage. Availability in restrictive countries changes frequently.
Will reinstalling fix a server timeout?
Usually not if the same timeout occurs on several devices or only on one network. Test server, protocol, and network first.
When is a different provider the right answer?
When several supported protocols and servers fail across devices and networks, or the provider lacks the platform and restricted-network features your regular use requires.