✎VPN Notes
Feature

The VPN Says Connected. Nothing Loads. Check These in Order.

Separate a dead internet connection from a VPN route, DNS, kill-switch or MTU problem with six reversible checks.

VPN Notes Editorial Team · 3 min read

A VPN app can show Connected even when useful traffic cannot pass. The tunnel handshake may have succeeded while DNS, routing or packet size still fails. Randomly reinstalling the app destroys clues. A short sequence of checks usually identifies the layer.

Change one thing at a time and restore privacy controls after the test.

1. Confirm the ordinary connection

Disconnect the VPN and open two unrelated HTTPS sites. If neither loads, the VPN is not the first problem. Reconnect Wi-Fi or Ethernet, confirm the device received an address, and test another device on the same network.

If ordinary internet works, reconnect the VPN and continue. Do not leave it disconnected if the network itself is untrusted; move to a trusted connection for testing.

2. Change only the server

Choose another server in the same country. A single gateway may be unhealthy or full even though the control service accepted the connection. If the second server works, the device configuration is probably sound.

If every server fails, the problem is more likely local configuration, protocol blocking or an account-wide service issue.

3. Test whether DNS is the failure

DNS turns a name such as example.com into an address. A tunnel can carry traffic while name lookups fail, making the entire web appear offline.

Try reaching a known service by an address only if you already have a trustworthy address for it; public addresses change, so this is a diagnostic clue rather than a permanent bookmark. Better, use the operating system’s DNS diagnostic tool and compare results connected and disconnected.

If address traffic works but names fail, return the VPN app’s DNS setting to its default. Remove a manually configured encrypted-DNS or filtering profile temporarily. Two tools trying to own DNS at once is a common conflict.

Do not solve the symptom by permanently sending DNS outside the tunnel without understanding the privacy trade-off.

4. Inspect the kill switch

A kill switch blocks ordinary traffic when the protected route is unavailable. Some apps leave that firewall rule active after a crash or failed reconnect.

Turn the kill switch off briefly on a trusted network, reconnect and test. If traffic returns, update the app and recreate the setting. Then turn the kill switch back on and test failure behaviour deliberately. The fix is not to abandon the control; it is to repair the rule that became stuck.

Also check whether an “allow LAN,” “block connections without VPN” or always-on VPN setting is enforced by the operating system. Corporate device management may prevent changes.

5. Change protocol

Some networks block or mishandle a transport. Switch between the app’s supported protocols, commonly WireGuard, OpenVPN UDP, OpenVPN TCP or IKEv2. TCP-based fallback may cross restrictive networks more reliably, though tunnelling TCP traffic inside TCP can perform poorly when packets are lost.

If one protocol consistently works on the same server and network, record that result. It points to network filtering or a protocol-specific adapter problem rather than bad credentials.

6. Suspect packet size when only some pages fail

An MTU problem often looks partial: small pages load, large pages hang, or messages send while attachments fail. The encrypted tunnel adds headers, making each packet larger. If the path cannot carry that size and the necessary error messages are blocked, packets disappear.

Use the VPN app’s automatic MTU setting first. If it offers a documented lower-MTU option, reduce it in small steps and retest. Avoid copying an arbitrary number from a forum; the right ceiling depends on the underlying network and protocol.

Preserve the result

Write down the network, server, protocol and single setting that changed the outcome. Then restore the original state and repeat once. A result that survives the repeat is far more useful than a pile of simultaneous changes.

If none of the checks helps, collect the app version, operating system, timestamps and sanitized diagnostic log for support. Remove account tokens, public addresses and browsing details before sharing it. “Connected but no internet” is only the symptom; these checks turn it into a route, DNS, firewall, protocol or packet-size problem.