Guides

VPN connected but no internet: how to find the cause

The app says Connected, yet nothing loads. Check captive portals, the kill switch, DNS, the server and network changes to get back online in minutes.

The app shows Connected, but pages keep spinning, messengers wait for a network and nothing downloads. This is a different problem from a VPN that will not connect: the tunnel was set up, but traffic is not getting through it. The causes below are sorted from the most common to the rarest, so work through them in order.

A 30-second check first

  1. Disconnect the VPN and open any website. If nothing loads now either, the problem is the network itself, not the VPN.
  2. Connect again and open our What is my IP tool. If it loads and shows the server's country, the tunnel works and only certain sites or apps are affected: jump to section 6.
  3. If even that page does not load, continue with section 1.

1. The network changed under the tunnel

The most common case: you walked out of Wi-Fi range and the phone switched to mobile data, or a laptop woke from sleep on a different network. The connection to the VPN server belonged to the old network, and packets sent over it now go nowhere.

The Windows app checks every two seconds whether the tunnel still carries traffic and reconnects by itself if it does not. On any platform, if the app still says Connected after a network change and nothing loads, disconnect and connect again. Adaptive Connect then tries the transports again and keeps the first one that actually carries traffic on the new network.

2. A Wi-Fi sign-in page is waiting

Hotels, airports, trains and cafés often use a captive portal: until you accept the terms or enter a code, the network lets almost nothing out. Many portals also end your session after a set time or data allowance, so a VPN that worked for an hour can suddenly stop.

  1. Disconnect the VPN.
  2. Open any plain http address, or tap the system's "Sign in to network" notification.
  3. Complete the sign-in and check that a normal site opens.
  4. Connect the VPN again.

On Android, if Block connections without VPN is switched on, the sign-in page may not appear while the VPN is down. Turn that option off for a moment, sign in, then turn it back on.

3. The kill switch is holding traffic back

A kill switch blocks traffic while the tunnel is down so that nothing leaves your device outside the VPN. The side effect is that a broken tunnel looks exactly like "no internet". That is intended: fix the tunnel rather than switching the protection off.

  • Windows: Colitu's kill switch uses the Windows Filtering Platform and is on by default. In TUN mode it is active for the whole session; in system proxy mode it engages when the tunnel is lost. If the app is reconnecting, give it a few seconds; if it cannot reconnect, choose another location. If the app crashes, Windows removes the filters itself, so a crash does not cut you off for good.
  • Android: the kill switch is Android's own Always-on VPN together with Block connections without VPN. While the VPN is reconnecting, no app can reach the internet. If it stays that way, open Colitu and connect again or pick another location.
  • Linux (beta): the kill switch uses nftables and works in TUN mode only; access to your local network stays allowed.

Details are in the help centre article on the kill switch.

4. The server or the route has a problem

A server may be overloaded, restarting or temporarily unreachable from your network. Check the servers page or status.colitu.com, then choose another location in the app.

Good to know: when you pick a location, the panel prefers the least-loaded server there and keeps that choice for your device for 24 hours. Reconnecting to the same location therefore usually lands on the same server, so switching to a different location is the fastest way to test another one.

5. DNS does not answer

Before a site can load, your device has to look up its address through DNS. If those lookups fail, browsers report "site not found" or a DNS error, while apps that connect straight to an IP address may keep working.

  • Disconnect and connect again: Colitu sends DNS lookups through the tunnel, and a fresh connection resets that path.
  • If you set a custom DNS server on the network adapter, in the router or in another app, remove it for a test.
  • In the browser, set Secure DNS (Chrome, Edge) or DNS over HTTPS (Firefox) to its automatic or default setting.
  • When pages load again, run the DNS leak test to confirm that lookups go through the tunnel.

6. Only some sites or apps fail

If What is my IP opens but a particular site or program does not:

  • The site may refuse addresses from data centres or from the server's country. Try another location.
  • On Windows the default mode is system proxy. Programs that ignore the system proxy, such as some games, launchers and desktop apps, then bypass the VPN. Turn on TUN mode so that all traffic goes through the tunnel.
  • On Windows and Android, Colitu sends Russian sites directly rather than through the tunnel, except on the Moscow server from version 2.5.3. This is built in and has no switch; if a Russian site fails, check it with the VPN off as well.
  • Split tunnelling (leaving chosen apps outside the VPN) is not available in Colitu at the moment.

More tips: a site does not open.

7. Windows: a proxy setting left behind

In system proxy mode Colitu sets the Windows proxy while it is connected. If the app was ended abnormally, for example from Task Manager, browsers can keep sending traffic to a proxy that is no longer running, and nothing loads even with the VPN off. Start Colitu and disconnect normally, or open Settings → Network & internet → Proxy and switch off the manual proxy.

Quick reference

SymptomLikely causeWhat to do
Stopped after changing networksOld connectionDisconnect and connect again
Hotel, train or café Wi-FiCaptive portalDisconnect, sign in, reconnect
App is reconnecting, nothing loadsKill switch holding trafficWait, then change location
"Site not found" everywhereDNSReconnect, remove custom DNS
One site or one program failsSite rules or proxy modeOther location, TUN mode

Still nothing?

Contact support through the live chat on the support page or at support@colitu.com. Tell us your device and app, your network (mobile operator or Wi-Fi), the location you chose and when the problem started. The help centre also has a full connection problems checklist.

Sources