VPN Not Connecting? Causes, Error Codes and Fixes

Published:

16 minute read

Acar Diveroli
Written by: Acar Diveroli
Isometric VPN gateway with vents, screws and an unlit VPN light; plates marked 691, TIMEOUT, AUTH and a blue 809 float above

You press Connect in your VPN app and the circle keeps spinning, until it gives up with "Couldn't connect" or Windows shows a box with a number such as 809 or 691. It worked yesterday at home and fails today on hotel Wi-Fi, or it is the work laptop and you need the company network in ten minutes.

This post is about a VPN tunnel that never comes up. We go through the quick checks, the steps a VPN takes while it connects, app protocols, the network you are on, phone settings, the Windows error codes with Microsoft's meaning for each, firewalls, routers and the server side. If your app says Connected but pages don't load, see VPN Connected but No Internet? Causes and Fixes instead.

What does "VPN not connecting" mean?

A VPN (virtual private network) puts your device's traffic into an encrypted tunnel that ends at a VPN server, as explained in What Is a VPN and How Does It Work?. "Not connecting" means the tunnel is never built: the app stays on "Connecting" or shows an error, while your normal internet keeps working.

The failure usually has one of two shapes. A long wait that ends in a timeout means the server never heard you. A quick refusal about your password, account or a certificate means the server heard you and said no.

How does a VPN connect, step by step?

  1. The app looks up the server's address. A name such as vpn.example.com is turned into an IP address by DNS, the internet's address book. If the name cannot be found, Windows shows error 868.
  2. The first packets travel to the server through your Wi-Fi, router, internet provider and any firewall in between. If one of them drops the packets, the app times out; Windows shows 809.
  3. The two sides check each other with a certificate (a digital ID card) or a pre-shared key (a shared password for the connection). A certificate is valid only between two dates, so a wrong device clock can fail here. For L2TP connections, Windows reports this step as 789.
  4. You sign in. A wrong password or an expired account stops the connection; on Windows that is 691.
  5. The server checks its rules, such as which sign-in methods it accepts. A mismatch gives 812.
  6. The tunnel opens and the app shows Connected. On Windows a blue shield appears on the taskbar.

Quick checks before anything else

  1. Turn the VPN off and open a website. If nothing loads, the problem is your internet connection, not the VPN.
  2. Check the account. On the provider's website, confirm the subscription is active and the device limit is not reached. For a work VPN, check that your work password has not expired.
  3. Set the date and time to automatic. Windows: Settings > Time & language > Date & time > Set time automatically. iPhone: Settings > General > Date & Time > Set Time Automatically. Android: Clock app, Settings > Change date and time > Automatic date and time.
  4. Update the app, restart the device and pick another server.
  5. Try another network. Connect the laptop to your phone's hotspot, or switch the phone from Wi-Fi to mobile data.

The last check splits the problem in two. If the VPN connects on the other network, your device and account are fine and the first network is the cause.

Common causes at a glance

What you seeMost likely causeWhat to try
Long wait, then a timeout or 809The network, a firewall or the router drops VPN trafficHotspot test, then router and firewall
Fails only on hotel or airport Wi-FiThe Wi-Fi login page is not completedFinish the page with the VPN off, then connect
Fails only at work or schoolThe network does not allow VPNsAsk the network administrator
Quick password error or 691Wrong details, expired password or accountRetype, reset the password, check the subscription
Server name error or 868Typo in the address, or a DNS problemCheck the address, try another network
Certificate errorWrong date and time, or an expired server certificateAutomatic time, then tell the provider or IT
Stopped after installing security softwareIts firewall blocks the VPN appAdd the VPN app as an exception
Phone VPN drops in the backgroundBattery saving limits background appsTest with battery saving off

App VPNs: what the protocol setting means

Provider apps usually have a Protocol or VPN type option. What matters is the traffic each one uses:

  • WireGuard, a newer and lightweight protocol, sends all of its packets over UDP, the kind of traffic that doesn't wait for a confirmation (see TCP vs. UDP).
  • OpenVPN, a widely used open-source protocol, runs over UDP or TCP depending on the provider's setup.
  • IKEv2/IPsec is built into Windows, iPhone and Mac, copes well with switching between Wi-Fi and mobile data, and needs UDP ports 500 and 4500 to pass.

A network that passes web pages but not UDP, or not those ports, lets the browser work and stops the VPN. If your app offers more than one protocol, switching once is a fair test at home or on a hotel network; if one connects and the other doesn't, tell the provider. Two more causes sit in the app itself: a second VPN app running at the same time (quit one) and a damaged install (uninstall, restart, reinstall from the official store).

Is the network blocking the VPN?

Hotel, café and airport Wi-Fi. Many public networks first show a login page, a captive portal, where you accept terms or type a room number. Until you finish it, the network blocks everything else, the VPN included. Turn the VPN off, open any website so the page appears, complete it, then connect. More on these networks in Is Public Wi-Fi Safe?.

Work and school networks. Many organisations don't allow VPN connections on their network, so that traffic goes through their own security checks. If the VPN fails only there, that is the rule working; ask the administrator instead of trying to work around it.

Countries. Some countries and networks restrict VPNs; this post does not cover that situation. Whether using a VPN is legal where you are is explained in Is Using a VPN or Proxy Legal?.

iPhone and Android: phone-specific causes

iPhone. VPN services usually come as an app, while work and school VPNs often arrive as a configuration profile listed under Settings > General > VPN & Device Management. A VPN profile left over from an old job or app can get in the way; remove only the ones you know you no longer need, and never your employer's without asking. The last resort is Settings > General > Transfer or Reset iPhone > Reset > Reset Network Settings. Apple's reset guide says it removes saved networks and the VPN settings not installed by a configuration profile or device management, so you will set up Wi-Fi and the VPN app again.

Android. VPNs live under Settings > Network & internet > VPN (search for "VPN" if your phone maker names it differently). A VPN added there by hand has an Always-on VPN switch behind its settings icon; Google's Android VPN help page notes that VPNs set up through an app don't have this option there, so look in the app's own settings. Battery saving is the other usual suspect: Settings > Battery > Battery Saver limits background activity, and Google warns that network connections can be delayed. If the VPN drops while the screen is off, try once with Battery Saver off.

Windows built-in VPN error codes

Windows' own VPN client, under Settings > Network & internet > VPN, shows a numbered error when it fails; many work VPNs use it. The meanings come from Microsoft's Routing and Remote Access error code list; the advice for 800, 809 and 812 follows its Always On VPN troubleshooting guide.

CodeMicrosoft's meaning, in plain wordsWhat to try
691The user name, the password or both were not acceptedRetype with Caps Lock off, use the exact user name format, reset an expired password
720No PPP control protocols are configured: the two sides could not agree on basic connection settingsCheck VPN type; if it is right, send the code to whoever runs the server
789An L2TP connection failed in its security step while first talking to the serverCompare the pre-shared key or certificate with your details
800The connection could not be made: the server may be unreachable, or security settings are wrongSet the exact VPN type instead of Automatic; try another network
809The server did not respond; a firewall, NAT or router in between may not allow VPN connectionsHotspot test, router passthrough, firewall; the server side must allow UDP 500 and 4500
812A rule on the VPN server stopped the connection; its sign-in method may not match your profileContact the administrator
868The name of the VPN server could not be resolvedCheck Server name or address; try another network

To change these settings, open Settings > Network & internet > VPN, select the connection, then Advanced options and Edit, as Microsoft's Windows VPN help page shows. On Automatic, Windows tries several tunnel types and reports 800 when all fail. If 868 appears for a name that worked before, the network's DNS server may be at fault; What Is DNS? shows how to change it. Company clients such as FortiClient, GlobalProtect and Cisco Secure Client show their own messages, but the same steps apply.

Firewall, antivirus and the router

Security software. After an update, a security suite's firewall can start blocking a VPN app it used to allow. Pause the firewall for a minute, try to connect and turn it back on right away. If the VPN connects while it is paused, add the VPN app as an exception instead of leaving protection off. On a work computer, leave this to IT.

VPN passthrough. Your home router gives every device one shared public address by rewriting the address on each packet, a technique called NAT. The older VPN types, PPTP and L2TP/IPsec, send traffic the router has to recognise before it can pass it on; the router feature for this is usually called VPN passthrough and is often on by default. If Windows shows 809 or 800 only at home, open the router's settings page (the address is usually on a label on the router), make sure VPN or IPsec passthrough is on and restart the router. WireGuard and OpenVPN normally don't need it.

A VPN server in your own home. If you reach home through a VPN on your own router, your home's public address may have changed, as Static IP vs Dynamic IP explains. If your provider puts your line behind CGNAT, connections from outside cannot reach your home at all; What Is CGNAT? shows how to check.

When the server side is the problem

If the VPN fails on every network and device while other servers work, or the provider reports an outage, the fault is not on your side. Choose another location, sign out and back in, then contact support. A company VPN can also fail for reasons you can't see, such as an expired server certificate or a changed sign-in rule; 812 is one of these. Don't install a second VPN to get around it. Send support or IT the exact message or code (a screenshot is best), the time, the network you were on, whether the hotspot test also fails and the app version.

When is a proxy the better tool?

A VPN changes the route of the whole device. If you only want one browser or program to use an address in another country, for example to check how your own online shop shows prices in another market, a proxy changes the route of that program alone. Residential Proxy give you home-connection addresses in the country and city you choose, and SOCKS5 Proxy work in any program with a SOCKS5 field. The comparison is in Proxy vs. VPN. A proxy does not replace your employer's VPN or encrypt your traffic on public Wi-Fi; for those jobs, fix the VPN.

Advanced: check whether the VPN server can be reached

This section is for readers comfortable with the command line. Windows PowerShell can test whether a server answers on one port; replace example.com with your VPN server's address and 443 with the port your provider or IT team uses:

powershell
Test-NetConnection example.com -Port 443

When the server can be reached, the output (shortened here) looks like this:

text
ComputerName     : example.com
RemoteAddress    : 104.20.23.154
RemotePort       : 443
TcpTestSucceeded : True

A warning that says Name resolution of … failed matches error 868. TcpTestSucceeded : False means nothing answered on that port, as with 809. True means the server can be reached, so check the sign-in details and the protocol. The test covers TCP only; for WireGuard and IKEv2, which use UDP, rely on the hotspot test.

Common mistakes

  • Reinstalling everything before the hotspot test. Two minutes on another network show whether the device is the problem at all.
  • Typing the password again and again. Many services lock an account after repeated failures.
  • Leaving VPN type on Automatic when you know which type to use.
  • Pausing the firewall and forgetting it. Add an exception for the VPN app instead.
  • Trying to get past a work or school network's rules. On their network, their policy decides.

Decision guide

Your situationWhat to do
Fails on every networkCheck the account, update the app, try another server, then contact the provider
Fails on one network onlyHotel: finish the login page. Work or school: ask the administrator. Home: check the router
Password error or 691Retype or reset the password, check the subscription
809 or a timeout at home onlyTurn on VPN passthrough, check the firewall, restart the router
800Set the exact VPN type instead of Automatic
868Check the server address and the network's DNS
812 or a certificate errorAutomatic date and time, then contact the provider or IT
You need another country's address in one app onlyUse a proxy in that app

Frequently asked questions

Why does my VPN connect on mobile data but not on Wi-Fi?

Something on that Wi-Fi network drops the VPN traffic: an unfinished login page, a router setting or a network rule. Your device and account are fine. At home, check the router; elsewhere, ask whoever runs the network.

Does a VPN that won't connect mean it has been blocked?

Not necessarily. Expired accounts, wrong clocks, busy servers and local firewalls cause many failures. If the VPN fails on one network only, that network refuses it; if it fails everywhere, look at the device, the account or the provider.

What is error 809 and how do I fix it?

The VPN server did not answer, and Microsoft says a firewall, NAT device or router in between may not allow VPN connections. Try another network first; if that works, check the router's VPN passthrough and your firewall. For a work VPN, tell IT, because the server side may need UDP ports 500 and 4500 open.

Why does the VPN say my password is wrong when it is right?

Check Caps Lock, the keyboard language and the user name format; some work VPNs expect domain\name. Some providers issue separate VPN credentials on your account page. An expired or locked account gives the same error, 691 on Windows.

Will resetting network settings on my iPhone delete my VPN?

Partly. Apple says it removes the VPN settings that were not installed by a configuration profile or device management, so open the VPN app afterwards to set it up again. Work VPNs installed through a profile stay.

Should I change the VPN protocol if it won't connect?

At home or on a hotel network, trying the app's other protocol once is a reasonable test, because some networks pass one kind of traffic and not another. On a work or school network, follow the administrator's rules.

Summary

A VPN that won't connect stops at one of a few steps: the server name, the network path, the identity check, the sign-in or the server's rules. Check the internet without the VPN, the account, the date and time, the app and the server, then run the hotspot test to tell the device from the network. Hotel Wi-Fi needs its login page first; work and school networks follow their own rules. On Windows, 868 points at the name, 809 and 800 at the path, 789 at the security check, 691 at the password and 812 at a server rule. If all you need is another country's address in one program, a proxy is the simpler tool; the options are on our proxy page.

Ask ChatGPTAsk Claude