T

TechyLeakz

Latest Fixes

Fix Guide

How to Fix a VPN Connected but No Internet on Windows

Fix a VPN that says connected but has no internet on Windows 10 and 11, starting with DNS and server changes. Then work through kill switch, IPv6, MTU, and adapter fixes.

Direct answer

When a VPN shows connected but pages won't load, the tunnel is usually up but traffic or DNS lookups aren't getting through. First confirm your internet works with the VPN off, and complete any public Wi-Fi sign-in page. Then switch to a different server and protocol, such as OpenVPN TCP instead of WireGuard, since some networks block UDP. If that fails, flush DNS with ipconfig /flushdns and use the VPN's own DNS, check for a stuck kill switch, and test with IPv6 disabled. Firewall conflicts, damaged virtual adapters, and MTU problems are the next suspects, and a clean reinstall or Windows network reset is the last resort.

Common causes

  • The VPN's DNS servers aren't responding or conflict with a custom DNS setting, so websites fail to load even though the encrypted tunnel itself is connected.
  • The server you're connected to is overloaded, under maintenance, or blocked on your network, so traffic enters the tunnel but never reaches the wider internet.
  • Your network blocks the protocol or port the VPN uses, which is common on hotel, school, and workplace Wi-Fi that filters the UDP traffic WireGuard relies on.
  • A kill switch or network lock stayed active after the app crashed or disconnected, leaving firewall rules in place that block all traffic outside the tunnel.
  • IPv6 traffic isn't routed through the VPN correctly, so some requests stall or are blocked by the app's leak protection instead of reaching the web.
  • An MTU mismatch causes larger packets to be dropped, so small requests work but full pages, downloads, and secure sites hang or load only partially.
  • Third-party firewalls, antivirus web shields, or another VPN client conflict with the tunnel, or the TAP, Wintun, or WireGuard virtual adapter is damaged or disabled.
  • A public Wi-Fi sign-in page hasn't been completed, or the router or network administrator blocks VPN connections outright.

Advertisement

Step-by-step fixes

Step 1

Confirm your connection works without the VPN

Disconnect the VPN and try loading a few websites. If nothing loads with the VPN off either, the problem is your underlying connection, not the VPN, so restart your router and PC first. On hotel, airport, or café Wi-Fi, open a browser with the VPN off and complete the network's sign-in page, because the VPN can't connect properly through a sign-in page you haven't accepted. Then reconnect the VPN. To tell a DNS problem from a routing problem, open Command Prompt while connected and run ping 1.1.1.1, then ping example.com. If the first gets replies but the second says it could not find the host, the tunnel works and DNS is the problem, so jump to the DNS step below. If both fail, keep working through the steps in order.

Step 2

Switch to a different server and protocol

A busy or faulty server is a very common cause, so connect to a different server in the same country, or pick one close to you. If that doesn't help, change the protocol in the VPN app's settings. Most apps let you choose between WireGuard-based options (NordLynx in NordVPN, WireGuard in Surfshark and Proton VPN), Lightway in ExpressVPN, and OpenVPN. Try OpenVPN TCP, or Lightway TCP in ExpressVPN, because many restrictive networks block the UDP traffic that faster protocols rely on, while TCP connections, often on port 443, look more like normal secure web traffic. If your provider offers obfuscation, such as NordVPN's obfuscated servers or Proton VPN's Stealth protocol, try it on networks that block VPNs. Success looks like pages loading normally within a few seconds of connecting.

Step 3

Flush DNS and use the VPN's own DNS servers

Open Command Prompt as administrator (search for cmd, right-click it, and choose Run as administrator) and run ipconfig /flushdns. You should see a message confirming that the DNS Resolver Cache was flushed. Then run ipconfig /registerdns and reconnect the VPN. Next, check the VPN app's settings for a custom DNS option; if you've entered your own DNS servers there, switch back to the provider's DNS, which is designed to work inside the tunnel. Also check Windows itself. In Windows 11, go to Settings > Network & internet > Wi-Fi (or Ethernet) > Hardware properties, click Edit next to DNS server assignment, and choose Automatic (DHCP). In Windows 10, run ncpa.cpl, right-click your adapter, choose Properties, open Internet Protocol Version 4 (TCP/IPv4), and select Obtain DNS server address automatically. Test with nslookup example.com while connected.

Advertisement

Step 4

Clear a stuck kill switch

If you have no internet even with the VPN disconnected, a kill switch has probably left blocking rules in place. Open the VPN app, connect to any server, then disconnect normally so the app can remove its own rules. If that doesn't work, go to the app's settings and turn off the kill switch (ExpressVPN calls it Network Lock, and Proton VPN's advanced kill switch keeps blocking traffic even when the VPN is off), then fully quit the app by right-clicking its icon in the system tray and choosing Quit or Exit. Restart the PC and test your connection. Once everything works, turn the kill switch back on, because it protects you if the VPN drops unexpectedly. If blocking persists after a restart, reinstalling the VPN app, covered in the final step, removes leftover rules.

Step 5

Test with IPv6 disabled

Some networks provide IPv6 addresses that a VPN app doesn't tunnel, and the app's leak protection may block that traffic instead, causing stalls. First check whether your VPN app has an IPv6 leak protection setting and make sure it's turned on. To test Windows itself, press Windows + R, type ncpa.cpl, and press Enter. Right-click your active Wi-Fi or Ethernet adapter, choose Properties, uncheck Internet Protocol Version 6 (TCP/IPv6), and click OK. Disconnect and reconnect the VPN, then try loading pages again. If the problem disappears, you can leave IPv6 off on that adapter while you use the VPN, or ask your provider whether an app update handles IPv6 better. If nothing changes, re-enable IPv6, because turning it off without a reason can cause problems with some apps and networks.

Step 6

Lower the MTU if pages load only partially

If small pages work but larger pages, secure sites, or downloads hang, packets may be too large for the tunnel. Check whether your VPN app has an MTU setting and try a lower value such as 1400, then 1350. To see current values, open Command Prompt as administrator and run netsh interface ipv4 show subinterfaces, which lists each adapter's MTU. You can test packet sizes with ping 1.1.1.1 -f -l 1372. If Windows replies that the packet needs to be fragmented but DF is set, reduce the number until pings succeed, then add 28 to get your working MTU. To set it on the VPN adapter, run netsh interface ipv4 set subinterface "Adapter Name" mtu=1400 store=persistent, using the exact name from the list. VPN apps may recreate their adapter on each connection, so an in-app setting is more reliable.

Step 7

Check firewalls, antivirus, and virtual network adapters

Security software can block VPN traffic even after the tunnel connects. In Windows Security, go to Firewall & network protection > Allow an app through firewall, click Change settings, and make sure your VPN app is allowed on private and public networks. If you use a third-party antivirus or firewall, add the VPN app as an exception or pause its web protection briefly to test, then turn it back on. Uninstall any other VPN clients you no longer use, since competing adapters and routes cause conflicts. Then right-click Start, open Device Manager, expand Network adapters, and choose View > Show hidden devices. Look for your VPN's adapter, such as TAP-Windows Adapter V9, Wintun, WireGuard Tunnel, or one named after your provider. If it shows a warning icon, right-click it, choose Uninstall device, and reinstall or repair the VPN app to recreate it.

Step 8

Reinstall the VPN app, then reset the Windows network stack

If nothing else works, uninstall the VPN app from Settings > Apps > Installed apps in Windows 11 (Settings > Apps > Apps & features in Windows 10), restart, and install the latest version from the provider's official website. This recreates the virtual adapter and clears leftover firewall rules. If the problem remains, reset the network stack: open Command Prompt as administrator, run netsh winsock reset and then netsh int ip reset, and restart. As a final step, use Network reset. In Windows 11, go to Settings > Network & internet > Advanced network settings > Network reset; in Windows 10, go to Settings > Network & Internet > Status > Network reset. Be aware that this removes and reinstalls all network adapters, deletes saved Wi-Fi networks and passwords, and may mean reinstalling VPN and virtualization software afterward.

How to prevent it

  • Keep your VPN app updated so protocol, adapter, and DNS fixes are applied promptly.
  • Use only one VPN client on a PC and fully uninstall any you stop using.
  • Switch to a TCP or obfuscated protocol on hotel, school, and workplace networks that block VPNs.
  • Complete any public Wi-Fi sign-in page before turning on the VPN.
  • Quit the VPN app normally instead of force-closing it, so the kill switch can remove its rules.

Tools that can help

The built-in Windows steps above fix most VPN connection problems without extra software. If your current app has no protocol choices or obfuscation, or keeps breaking your connection after updates, a well-maintained VPN with modern protocols and responsive support is worth trying under a money-back guarantee.

Top pick

NordVPN

NordVPN pairs its fast NordLynx protocol with audited no-logs claims, RAM-only servers, and apps for computers, phones, Android TV, and Fire TV. A 30-day money-back guarantee applies to direct purchases.

Visit NordVPN

Best value

Surfshark

Surfshark covers unlimited devices on one subscription and includes WireGuard, RAM-only servers, CleanWeb ad blocking, and Smart DNS for TVs. Long-term plans are usually priced below premium rivals.

Visit Surfshark

Best for privacy

Proton VPN

Proton VPN is Swiss-based, with open-source apps and an independently audited no-logs policy. Its free plan has no data cap, and paid plans add streaming support, Secure Core, and NetShield.

Visit Proton VPN

TechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure

What to do next if this fails

  • Move to the next fix instead of repeating the same step multiple times.
  • Check the related guides in this cluster before attempting a full reset.
  • If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.

Advertisement

FAQ

Why does my VPN say connected but nothing loads?

The app has established the encrypted tunnel, but traffic isn't making it through. The usual culprits are DNS lookups failing inside the tunnel, a busy or blocked server, a network that blocks the VPN's protocol, or a firewall rule left behind by the kill switch. Switching server and protocol, then flushing DNS, fixes most cases within a few minutes.

Is it the VPN or my internet connection?

Disconnect the VPN and try loading a website. If it still fails, the issue is your Wi-Fi, router, or internet provider, unless a stuck kill switch is blocking traffic. If everything works with the VPN off and fails with it on, the problem lies with the VPN's server, protocol, or DNS, or with a software conflict on your PC.

Why does my VPN work at home but not on public Wi-Fi?

Public and workplace networks often block the UDP traffic that WireGuard-based protocols use, or they require you to accept a sign-in page first. Complete the sign-in with the VPN off, then connect using OpenVPN TCP or an obfuscation feature such as NordVPN's obfuscated servers or Proton VPN's Stealth protocol. Some networks block VPNs entirely by policy.

Can antivirus software block my VPN?

Yes. Antivirus web shields, HTTPS scanning, and third-party firewalls can interfere with VPN traffic or with the virtual adapter the VPN creates. Add the VPN app as an exception in your security software, or briefly pause web protection to test. If that fixes it, keep the exception and turn protection back on right away.

Will a Windows network reset delete my files?

No. A network reset doesn't touch documents, photos, or installed apps. It removes and reinstalls network adapters, returns networking components to their defaults, and forgets saved Wi-Fi networks and passwords, so you'll need to reconnect to Wi-Fi afterward. VPN apps may need to be repaired or reinstalled because their virtual adapters are removed.

Should I turn off my VPN's kill switch?

Only temporarily, while troubleshooting. The kill switch stops your traffic from leaking outside the tunnel if the VPN drops, which is the main protection on public Wi-Fi. If it's leaving your PC without internet after you disconnect, update or reinstall the app so its rules are cleaned up properly, then turn the kill switch back on.

TechyLeakz

Search-first tech publishing focused on fixes, comparisons, and software recommendations.