VPN Connected but No Internet? Fixes for VLESS Reality Apps

TroubleshootingUpdated October 2, 20269 min read

"Connected" in a VPN app means one thing: the app has built the tunnel on your device. It does not mean the server at the other end answered, that the entry you picked is a real server, or that your network lets the traffic through. A green button with nothing loading is therefore common, and it usually has an ordinary cause. Work through the checks below in order. The first two take about a minute and rule out the causes on the account side.

Find your symptom

What you seeLikely cause
The location name is a sentence, such as "No active plan"An account notice, not a server. Check 1 →
Nothing loads on any location, on any networkA stale list, a wrong clock, another VPN app or a DNS setting. Checks 2, 4, 5, 6 →
One location fails, others workThat location is down or filtered from where you are. Check 3 →
Works on mobile data, not on this Wi-FiA login page, or a network that filters. Check 7 →
It worked until you changed a settingAn edited profile. Don't edit →
Pages load, but slowly or behind CAPTCHAsDistance, Wi-Fi quality, shared addresses. Slow or CAPTCHAs →

Check 1: are you connected to a real location?

Read the name of the entry you are connected to. Kovra, like many providers, delivers account notices as entries in the server list, because a server entry is the one thing every VPN app can display. These entries point nowhere on purpose, so the app reports "connected" and nothing loads. On Kovra this is the first thing to rule out.

  • No active plan - kovravpn.com. The account has no active plan. Renew in the dashboard, then refresh the subscription (check 2).
  • One device per link - kovravpn.com. This link belongs to another device. Use this device's own link, or press Reset device binding in the dashboard and refresh here straight away.
  • Subscription removed - kovravpn.com. This device was deleted in the dashboard. Add the device again and import its new link.

Happ also shows the matching message in a red info block. How these entries work, and why each device has its own link, is explained in what a subscription link is.

Check 2: refresh the subscription

The app works from the last copy of the server list it downloaded. If a location was replaced, or you renewed your plan since then, the old copy is wrong until the next refresh. Kovra asks apps to refresh every hour, but you do not have to wait: use the refresh control next to the subscription's name (a circular-arrow icon in Happ; its place varies by app and version), then reconnect.

If the refresh fails, read the error. Happ reports Timeout while adding a subscription when the subscription server does not answer within nine seconds. That means the list could not be downloaded from this network, which makes it a network question rather than an account one. Try again on mobile data or another Wi-Fi. The locations already in the app normally stay there in the meantime.

Check 3: switch location, then switch network

Two quick swaps separate a server problem from a network problem. First connect to a different location. If nothing works, switch between Wi-Fi and mobile data and try again.

ResultWhat it tells you
Another location worksThe first location is down or filtered from where you are. Use another one for now and tell support which one failed.
No location works on Wi-Fi, all work on mobile dataThe Wi-Fi network is the problem: a login page or a filter (check 7).
Nothing works anywhereThe cause is on the device or the account: checks 1, 4, 5 and 6.

Switching location is also the quickest workaround while you look for the cause. Kovra locations run VLESS with REALITY over TCP, so a different location means a different server, not a different protocol.

Check 4: date, time and time zone

A device clock that is far off breaks HTTPS certificate checks. That alone is enough to break the subscription refresh and many apps and websites, even while the tunnel is up. Set the date, time and time zone to automatic:

DeviceWhere to find it
iPhone, iPadSettings → General → Date & Time → Set Automatically
AndroidSettings → System → Date & time on most phones; Samsung keeps it under General management. Turn on automatic time and time zone.
WindowsSettings → Time & language → Date & time → Set time automatically
MacSystem Settings → General → Date & Time → Set time and date automatically

After fixing the clock, refresh the subscription and reconnect.

Check 5: another VPN, proxy or security app

Two tunnels on one device fight over the same traffic. Phones allow only one active VPN at a time, and apps that are not called "VPN" often take that slot: ad blockers, firewall apps, parental controls and some antivirus suites. Close or pause them and reconnect.

  • Android always-on VPN. If another app is set as the always-on VPN, Android keeps handing it the slot. Look under Settings → Network & internet → VPN (the path differs by manufacturer), open the gear next to other apps and turn always-on off for them.
  • Other VPN configurations on iPhone. Settings → General → VPN & Device Management → VPN lists every VPN configuration installed on the phone. Only one can be active, so check that the selected one belongs to the app you are testing.
  • Antivirus web shields. Features called web protection, HTTPS scanning or secure DNS intercept connections and can break VPN traffic. Pause them to test.
  • The leftover proxy on Windows. When a proxy app is closed uncleanly, Windows can keep sending browser traffic to a local proxy that no longer exists, so nothing loads whether the VPN is on or off. With every VPN and proxy app closed, open Settings → Network & internet → Proxy and, under manual proxy setup, turn off a proxy server that is still switched on (it often points to 127.0.0.1).
  • Work or school management. A managed device can force its own VPN or DNS settings. A personal VPN cannot override them.

Check 6: DNS and IPv6

If the tunnel is up but websites fail by name, DNS is the usual suspect. Put the settings back to their defaults:

  • Private DNS on Android. Settings → Network & internet → Private DNS (on Samsung: Connections → More connection settings). If it is set to a specific provider hostname, switch it to Automatic while testing. A DNS server that cannot be reached from your network breaks every lookup.
  • Custom DNS inside the VPN app. If you typed DNS servers into the client's settings, clear them. The imported profile works with the app's defaults.
  • DNS profiles on iPhone. An installed DNS app or configuration profile can take over name resolution. Check Settings → General → VPN & Device Management and disable it while testing.
  • IPv6 options. If you switched on IPv6-related options in the app, return them to their defaults.

Once pages load, confirm that nothing escapes the tunnel with the VPN leak test.

Check 7: a login page, or a network that filters

Hotel, airport, train and café Wi-Fi often holds all traffic until you accept terms on a login page, known as a captive portal. With the VPN on, that page often fails to appear, so the network quietly drops everything. Disconnect the VPN, open a plain-HTTP page such as neverssl.com or captive.apple.com to bring the login page up, sign in, then reconnect. The full routine is in VPN not working on hotel Wi-Fi.

Other networks filter on purpose. Workplaces, schools and some national networks block traffic that looks like a VPN, and they change their rules without notice. REALITY is built to resemble an ordinary HTTPS connection, but no protocol is certain to pass every filter, and nobody can honestly promise that one will. If a network blocks you while mobile data works, the network is the cause. Where a country restricts VPN use, check the local rules before trying to get around a block.

Don't edit the imported profile

Forum threads about this problem are full of advice to switch on Mux, change the SNI, pick another fingerprint or remove the flow. In a REALITY profile the SNI, keys and flow have to match what the server expects, and Mux is known to break connections that use the Vision flow. Your provider has already set these values, and changing them usually turns a working profile into one that connects and carries nothing. Kovra's subscription asks Happ to hide the server settings, so this mostly concerns other apps.

If you have already changed settings, don't undo them one by one. Delete the subscription from the app and import your link again from the dashboard. On Kovra, re-importing on the same device does not affect the device binding.

Connected, but slow or full of CAPTCHAs

If pages load but badly, the causes are different:

  • CAPTCHAs. VPN servers live in datacentres, and many users share each address. Some sites treat shared datacentre addresses with suspicion and ask for more CAPTCHAs. Switching location sometimes helps. This is a trait of VPNs in general, not a fault in your setup.
  • Distance. Every request travels to the server and back, so a nearby location is usually faster than a distant one.
  • Wi-Fi quality. A weak signal or a crowded network slows everything, tunnel or not. Compare with the VPN off on the same network.
  • Fair use. Kovra's Terms (section 8) allow a temporary speed limit or a paused connection for atypical load, which they describe as including sustained maximum-speed use, large-volume peer-to-peer traffic, signs of reselling and automated connections. If you run long full-speed transfers or heavy peer-to-peer traffic, that clause can apply.

What to send support

If the checks don't solve it, a precise report gets a precise answer. Write to @KovraVPN_bot on Telegram or [email protected] with:

  • Your device and app, with versions if you can see them (for example "Android 14, Happ").
  • The exact name of the location you connected to.
  • The network: Wi-Fi or mobile data, and which country you are in.
  • What you have already tried from this list.
  • A screenshot of any error, with the subscription link cropped out.

Support finds your account from your Telegram or email. Share the link itself only inside the private support chat, never in a public group or comment thread. If the problem started right after a payment, the crypto payment troubleshooting guide may be the faster route.

Frequently asked questions

Why does my VPN say connected when nothing loads?

Because 'connected' only means the app built the tunnel on your device. It does not confirm that the server answered, that the entry is a real server, or that your network lets the traffic through. Check the entry's name first, then refresh the subscription, switch location and network, and check your clock and DNS.

Does resetting the device binding help?

Only when the entry you see is 'One device per link - kovravpn.com'. In that case reset the binding in the dashboard and refresh the subscription on this device straight away. For every other cause a reset changes nothing, and it lets whichever device refreshes next claim the link.

Will reinstalling the VPN app help?

Rarely on its own. It helps when settings were changed by hand, because a reinstall returns them to defaults. After reinstalling, import your link again. If the app then shows 'One device per link', the device identifier may have changed, so reset the binding in the dashboard and refresh.

Why does the VPN work on mobile data but not on Wi-Fi?

The Wi-Fi network is the difference. Often it is a login page that the VPN hides: disconnect, open neverssl.com to bring the page up, sign in and reconnect. If there is no login page, the network may be filtering VPN-like traffic, and mobile data or another network is the practical way round it.

Should I change the SNI, fingerprint or Mux settings to fix it?

No. In a REALITY profile the SNI, keys and flow have to match the server, Mux is known to break connections that use the Vision flow, and the provider has already chosen the fingerprint. Changing these values usually turns a working profile into one that connects and carries nothing. If you already edited settings, delete the subscription from the app and import the link again.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches