VPN Connected but No Internet? Causes and Fixes

Published:

14 minute read

Acar Diveroli
Written by: Acar Diveroli
A laptop, a ribbed tunnel, a VPN server marked CONNECTED and a DNS stack; the strip breaks before the blue INTERNET globe

You press Connect in the VPN app and the button turns green. Windows shows "Connected" under the VPN's name and a blue shield on the network icon. Then nothing loads: the browser ends on an error page and a video call drops. Turn the VPN off and everything comes straight back.

This guide covers that case: the app says it is connected, yet pages do not load. If the app never reaches "Connected", read VPN Not Connecting? instead. Below are a two-minute test, the usual causes in the order worth checking, what to tell IT about a work VPN and one optional command.

What does "connected but no internet" mean?

A VPN app says "Connected" once it has built a tunnel: an encrypted connection between your device and the VPN server that all your traffic travels inside. The status describes that tunnel only. It does not test whether the server can reach the rest of the internet.

On Windows, Settings > Network & internet > VPN shows Connected under the VPN's name; phones show a VPN icon at the top of the screen. Meanwhile the browser may show "No internet" or "server IP address could not be found" (ERR_NAME_NOT_RESOLVED); these errors are explained in This Site Can't Be Reached.

What happens to your traffic when you press Connect?

  1. The app and the server recognise each other and agree on encryption keys. Some protocols set the tunnel up on your device first: WireGuard's protocol page says you "bring the device up, and everything else is handled for you automatically".
  2. The VPN takes over the default route, the road your device uses for every address it has no more specific road for. OpenVPN's reference manual describes its redirect option this way: the VPN replaces the default gateway until the tunnel closes.
  3. The VPN sets its own DNS servers. DNS turns names such as example.com into IP addresses.
  4. Each packet is wrapped and sent to the server, usually over UDP, a way of sending data that does not wait for each piece to be confirmed. Wrapping makes every packet a little larger.
  5. The server sends the request on to the internet and passes the answer back.

"Connected" appears after step 2. Steps 3, 4 and 5 can still fail, and from your seat each failure looks the same: nothing loads.

Start with a two-minute test

  1. Turn the VPN off. If the internet still does not work, the VPN is not the cause; check your router.
  2. Connect to another server. If that works, the first server was overloaded or broken.
  3. Try another network, such as your phone's hotspot. If the VPN works there, the first network is the problem: an unfinished login page, or a network that does not carry VPN traffic.
  4. Quit the app completely and restart the device. Closing the window often leaves the app running.

Which cause fits what you see?

What you seeLikely causeFirst thing to try
"Server IP address could not be found"The VPN's DNS does not answerReconnect or change server; undo DNS you set by hand
Nothing loads on hotel or café Wi-FiLogin page not completedVPN off, sign in, VPN on
No internet since the VPN droppedThe kill switch is blocking trafficReconnect, or disconnect in the app
Began after adding a second VPN or a proxyTwo tools fighting over trafficKeep one; check proxy settings
"Your Internet access is blocked"Firewall or antivirusPause it briefly, then add an exception
Pages start loading, then stallPackets too large (MTU)Another server or protocol
Works on mobile data, not on one Wi-FiNetwork drops the VPN's UDP trafficThe app's other protocol option
Work sites open, public sites do notWork VPN routingTell IT

Why do sites fail by name when the VPN is up?

Before opening a site, your device asks a DNS server for its IP address. With the VPN on, it asks the servers the VPN handed over when it connected. If those are down or unreachable through the tunnel, the tunnel stays up and every name fails.

  • Reconnect, then try another server. A different server often comes with working DNS.
  • Undo DNS you set by hand. A custom provider in the browser's secure DNS setting, on the phone or on the network adapter can clash with the VPN's servers. Set it back to automatic for one test; What Is DNS and How Do You Change Your DNS Server? shows where these settings live.
  • Leave the app's DNS protection on. Turning it off can send lookups outside the tunnel, a DNS leak explained in WebRTC and DNS Leaks.

Why must the Wi-Fi login page come before the VPN?

Hotel, café and airport Wi-Fi often lets you out only after you accept terms on a login page, and until then it holds back everything else, including the VPN. Apple calls these captive networks; its help page says to open Settings > Wi-Fi, tap the network's name and wait for a login screen to appear.

A VPN that starts automatically reaches for its server before you have signed in. Turn the VPN off, complete the login page (on a computer, opening any website usually brings it up), then turn the VPN on. Some networks end the sign-in after a few hours.

Is the kill switch cutting you off?

A kill switch blocks all internet traffic when the tunnel drops, so that nothing leaves your device outside the VPN. Many VPN apps for computers have one, and Android has one built in: under Settings > Network & internet > VPN, the settings icon next to a VPN leads to Always-on VPN, and Google's help for managed devices describes Block connections without VPN, which cuts apps off whenever the VPN is not carrying their traffic. Google's Android VPN help adds that when an always-on VPN stops working, a notification stays until you reconnect.

So "no internet" after a drop is often the kill switch doing its job: reconnect, or disconnect properly inside the app. If the block stays after you quit, reopen the app and turn the kill switch off there. The last resort on Windows is Settings > Network & internet > Advanced network settings > Network reset; Microsoft's Wi-Fi troubleshooting page warns that you may need to reinstall VPN client software afterwards.

Can two VPNs, or a VPN and a proxy, clash?

Only one VPN can own the default route and DNS at a time, yet a second VPN app, a browser's built-in VPN or an ad blocker running as a VPN profile can each try to take over. Disconnect everything except the VPN you want, then reconnect it.

A leftover proxy is the other common clash. Windows has a system-wide setting under Settings > Network & internet > Proxy (Use a proxy server), and each VPN connection can carry its own: select the VPN under Settings > Network & internet > VPN, then Advanced options and Proxy settings for this VPN connection. A proxy you did not set is your lead; on a work VPN, ask IT first. Removing one is covered in Proxy Server Not Responding.

Is your antivirus or firewall blocking the VPN?

Apple's support article says third-party security software that monitors network connections can block some connections, including those needed to reach the internet. In Chrome, such a block can appear as "Your Internet access is blocked" and "Firewall or antivirus software may have blocked the connection." (ERR_NETWORK_ACCESS_DENIED).

Pause only the suite's firewall or web protection for a minute and reconnect. If pages load, turn protection back on and add the VPN app as an exception. On iPhone, Apple suggests swiping down in Settings to reveal the search field and searching for "VPN", "profile", "firewall" and "filter" (on a Mac, search System Settings); some ad blockers run as VPN profiles, listed under Settings > General > VPN & Device Management.

Why do pages load only halfway?

Every network has a largest packet it carries in one piece, the MTU. Wrapping makes a full-size packet slightly too big, and when a device on the route silently drops oversized packets, small pieces get through and large ones do not: a page's title appears, then it stalls. OpenVPN's manual says MTU problems "often manifest themselves as connections which hang during periods of active usage". Try another server or protocol, change an MTU setting only to a value the provider gives, and on a work VPN tell IT that pages "start loading, then stall".

IPv6, the newer and longer form of IP address, can give a similar picture: some VPNs carry only IPv4 and block IPv6 so it cannot slip around the tunnel. Browsers try both and use whichever answers; if one app hangs, ask the provider about the app's IPv6 setting.

What if the network does not carry the VPN's traffic?

WireGuard sends every packet over UDP ("All packets are sent over UDP", says its protocol page), and OpenVPN uses UDP by default; its manual says TCP support exists "for situations where UDP cannot be used". Some guest, hotel and office networks pass web traffic but drop other UDP traffic, and because WireGuard brings the tunnel up on your device first, the app can look switched on while nothing comes back.

If the VPN works on mobile data but fails on one network, and your provider's app offers another protocol option, try it there; TCP vs. UDP explains the difference. If an employer or school blocks VPNs on purpose, follow their policy. Some countries and networks restrict VPNs; this guide does not cover that, and the legal side is in Is Using a VPN or Proxy Legal?.

What should you tell IT about a work VPN?

FortiClient, GlobalProtect, Cisco Secure Client (formerly AnyConnect) and similar clients are set up by IT. In a full tunnel, all your traffic goes through the company network, so your internet works only while the company passes it on. In a split tunnel, only company traffic uses the VPN. Microsoft's article on the built-in Windows VPN shows the classic failure: Use default gateway on remote network sends all traffic to a remote network that does not pass it to the internet (Microsoft Learn).

Do not untick that box yourself; a full tunnel is often a security requirement. Tell IT instead whether the internet works with the VPN off, whether company sites open while public sites do not, which network you are on, the client's version, the exact error text and the time, plus the result of the command below if you ran it.

Advanced: what does route print show?

You can skip this section. On Windows, one command shows where the default route points:

powershell
route print 0.0.0.0

Run it with the VPN off, then on. Under Active Routes, each line starting with 0.0.0.0 is a default route; the columns are destination, netmask, gateway, interface and metric. With the VPN off there is usually one line, your router. If a second line appears with a lower metric (the last number), the VPN carries all traffic, because the route with the lowest metric is chosen (Microsoft's route reference). A netmask of 128.0.0.0 means the same: some VPNs cover the internet with two half routes.

If the VPN's route wins and nothing loads, tell your provider or IT: "full tunnel, default route through the VPN, no internet".

When is a proxy the better tool?

A VPN changes the route of the whole device, so a VPN fault takes everything offline. If you only need to see how a website or an ad looks from another country in one browser or tool, a proxy changes the route for that app alone.

  • One browser profile or tool: Residential Proxy let you choose the country and city.
  • Programs with a proxy field: SOCKS5 Proxy carry TCP and UDP traffic.

Proxynet sells proxies, not a VPN. A proxy does not encrypt the whole device, so on untrusted Wi-Fi and for company systems a VPN remains the right tool. See Proxy vs VPN and Smart DNS vs VPN vs Proxy.

Where does this happen most often?

Common mistakes

  • Leaving the antivirus or firewall off after a test.
  • Installing a second VPN to test the first. They fight over the same traffic.
  • Unticking "Use default gateway on remote network" on a work VPN. Company systems stop working.
  • Turning off the app's DNS protection for good. Lookups leave the tunnel.
  • Copying MTU values from forums instead of using the provider's figure.

Decision guide

SituationWhat to do
No internet with the VPN off eitherNot a VPN problem; check the router
Another server worksUse it; report the broken one
Works on a hotspot, not on this Wi-FiFinish the login page, then try the other protocol option
Employer or school blocks VPNsFollow the policy; ask the administrator
Work VPN, public sites deadSend IT what you saw
Another country's IP in one app onlyA proxy in that app

Frequently asked questions

Why does Chrome say "A network change was detected" when I connect?

Chrome shows "Your connection was interrupted" and "A network change was detected." (ERR_NETWORK_CHANGED) because the VPN added a network adapter mid-load. Reload once. If it keeps returning, the VPN is reconnecting in a loop; try another server.

Why can't I reach my printer or router page with the VPN on?

Some VPNs send home-network traffic into the tunnel; OpenVPN even has an option that blocks the local network. Many apps have a setting that allows local network access; a work VPN may block it on purpose.

Why does the internet not come back after I turn the VPN off?

The kill switch may still be active or the app still running. Open the app, disconnect and quit, then check for a proxy you did not set.

Why does only one site fail when the VPN is on?

The VPN works; that site refuses known VPN addresses or asks for extra checks. Try another server.

Why does it happen only on Wi-Fi and not on mobile data?

That Wi-Fi may still need its login page, or it drops the VPN's UDP traffic. Sign in, then try the app's other protocol option.

Is it safe to browse with the VPN off while I fix this?

At home, usually yes: sites that start with https:// stay encrypted. On public Wi-Fi the network can see which sites you visit, so wait if you can.

Summary

A VPN that says "Connected" while nothing loads has built its tunnel, but traffic stops after it: at the VPN's DNS, a Wi-Fi login page, a network that drops UDP, a kill switch, security software, oversized packets or the server itself. Turn the VPN off, change server, then change network, and the cause usually shows within minutes; with a work VPN, describe what you saw to IT. If you only need another country's address in one browser or tool, a proxy changes just that app's route; see our proxy services.

Ask ChatGPTAsk Claude