Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First check whether your internet still works with the VPN disconnected. If it does not, troubleshoot the Wi-Fi, router, or ISP; if it does, test another VPN server and then a different protocol or port supported by your provider. These checks help identify whether the drops come from the network path, the VPN service, or the device.

1. Check whether your internet connection is also dropping

Disconnect the VPN briefly and try ordinary browsing. If pages still fail to load, the VPN tunnel may not be the root cause: check the Wi-Fi signal, router, modem, or ISP connection first. Your VPN provider may also recommend testing another network to see whether the issue follows the current one. Private Internet Access troubleshooting guidance covers these checks.

If the internet stays reliable without the VPN, move on to testing the VPN server and connection settings. Keep track of whether ordinary internet access failed at the same time as each VPN drop; that distinction is useful throughout troubleshooting.

2. Find out whether the problem follows a server or network

Try another VPN server

Choose a different server in the VPN app and observe whether the connection stays up. If another server works, the problem may be limited to the original server or route. If every server drops, continue with the network and protocol checks rather than assuming the VPN service itself is at fault.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Try another network

If practical, connect through a different Wi-Fi network or a mobile hotspot. A VPN that stays connected there points toward the original network, router, firewall, or ISP as a possible cause. This is a diagnostic clue, not proof that a particular network is blocking VPN traffic; network restrictions are among several possible causes described in PIA’s connection troubleshooting guide.

Test Wi-Fi against Ethernet

On a Windows PC, a wired Ethernet connection can help determine whether Wi-Fi is unstable. Connect the PC to the router with an Ethernet cable; if the computer has no Ethernet port, Microsoft notes that a USB-to-Ethernet adapter may be an option. A wired test isolates the network path—it is not a guaranteed VPN fix. See Microsoft’s instructions for connecting to a Wi-Fi network in Windows and its Ethernet guidance.

3. Try a different VPN protocol or port

When ordinary internet access remains stable but the VPN disconnects, change one VPN setting at a time. Try another protocol or port that the provider supports, reconnect, and watch for a change in stability. Some networks interfere with or block particular VPN protocols or ports, but there is no single protocol that is best for every provider and network. PIA discusses protocol and network compatibility in its troubleshooting guide.

A tunnel can also be treated as unavailable when keepalive or data packets are lost or blocked. IVPN describes changing ports or trying WireGuard in supported native apps as possible troubleshooting steps; availability and results depend on the app and network. See IVPN’s guidance on dropped connections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Check device and Wi-Fi settings

Windows Wi-Fi power management

If VPN drops coincide with Wi-Fi interruptions on Windows, investigate the Wi-Fi adapter’s power-management setting and test with Ethernet. Microsoft’s Wi-Fi troubleshooting guidance covers frequent disconnections. Menu names and available controls can vary by Windows version and hardware, so use the instructions for your system.

Android always-on VPN

Android supports an always-on VPN behavior, and the system can notify you if that VPN cannot connect or disconnects. The exact controls depend on the Android release, device management, and VPN app. Consult the app’s current instructions and your device’s settings; always-on behavior helps enforce or retry a VPN connection but does not repair an unstable network.

Managed Apple devices and work VPNs

Apple’s managed IKEv2 declarative VPN configuration includes dead-peer detection keepalive options and optional disconnect-on-idle settings. These are configuration controls for managed VPN setups, not a universal switch for individual users. If a work or school device disconnects, ask its administrator before changing settings. Apple’s details are in its VPN configuration deployment documentation.

5. Set expectations for automatic reconnect and a kill switch

Automatic reconnect

Check whether your VPN app offers automatic reconnect and enable it if its behavior suits your needs. For example, Cisco Secure Client documents Auto Reconnect options, including behavior around system suspend and trusted-network detection. Other VPN clients may use different names or offer different controls; see Cisco Secure Client’s configuration guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Kill switch

A kill switch may block internet traffic that is not passing through the VPN when the tunnel drops. That can reduce exposure during a disconnection, but it can also make the device appear offline until the VPN reconnects. It does not stop the VPN tunnel from disconnecting. Behavior varies by platform; NordVPN describes its implementation in its kill switch support article.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. What to give VPN support or your administrator

If changing servers, supported protocols or ports, and networks does not isolate the cause, contact your VPN provider or workplace VPN administrator. Include:

  • Device model and operating system version
  • VPN app name and version
  • Protocol and port, if the app shows them
  • Server or location selected
  • Network type, such as home Wi-Fi, workplace Wi-Fi, Ethernet, or hotspot
  • Approximate times of the drops
  • Whether ordinary internet access also failed when the VPN disconnected

If the provider supports diagnostic logs, follow its official process to collect and share them. PIA’s connection troubleshooting guide includes logging and support escalation guidance. Share logs only through the provider’s official support route.

What not to change based on a generic VPN tip

Android Open Source Project network-operator guidance recommends a NAT and stateful-firewall timeout of at least 600 seconds for UDP port 4500 to support IPsec VPN reliability. That is a network-operator recommendation, not a timer for consumers to set in a VPN app. The guidance also notes that frequent keepalives can increase client power use and network signaling, and discusses ESP support as an alternative for compatible setups. See Android’s VPN documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For device-level keepalive, power, or managed VPN settings, follow the instructions for the specific operating system and app. A setting intended for a network operator or administrator may not be available—or appropriate—for an individual user.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.