VPN Not Working on Hotel or Airport Wi-Fi? Fix Captive Portals

TroubleshootingUpdated September 25, 20268 min read

The pattern is familiar. You join the hotel Wi-Fi, the VPN spins on "connecting", and nothing loads. Often the VPN is not being blocked at all. The network simply has not let you out yet, and the VPN is hiding the page that would. Here is what is going on and the order in which to fix it.

Why these networks break VPNs

Captive portals

A captive portal holds every new device at a login or terms page until you complete it. Your phone or laptop detects this by requesting a known plain-HTTP address from Apple, Google or Microsoft and checking whether the answer has been tampered with. If it has, the system opens the sign-in sheet. Depending on the system and the app, a VPN that captures all traffic can send that check, or the login page itself, into a tunnel which cannot open, so the sheet never appears or never loads.

DNS interception

Many portals answer every DNS lookup with their own address until you log in. Encrypted DNS can bypass that trick. Examples include Android's Private DNS set to a specific provider, secure DNS in Chrome and DNS over HTTPS in Firefox. Android and the browsers try to detect portals and step aside, but when that fails, the redirect never happens.

Port and UDP restrictions

Guest networks are often configured for web browsing and little else. Some block UDP apart from DNS, and some allow only a handful of ports. Both break common VPN setups even after you have logged in.

Client isolation and time limits

Client isolation stops guests from seeing each other's devices. That is good for security, but it is why casting to the room TV can fail, and it is not a VPN problem. Sessions are often time-limited or capped per room. When a session expires mid-stay, the portal silently returns and the VPN looks as if it has died.

The portal-first sequence

  1. Pause the VPN. Disconnect or pause it, and temporarily turn off any setting that blocks traffic when the VPN is down (see the next section).
  2. Join the network and wait a few seconds for the sign-in page.
  3. If nothing appears, open the page yourself. In a browser, go to http://neverssl.com or http://captive.apple.com. Both are deliberately plain HTTP, so the portal can intercept them. An HTTPS site cannot be redirected without a certificate warning.
  4. Complete the login. Enter the room number, surname or voucher code, and accept the terms. Enter no more than the portal genuinely needs.
  5. Confirm the connection is real. Load an ordinary website you have not opened recently. If it loads, the network is letting you out.
  6. Reconnect the VPN. Re-enable any blocking setting you paused, and refresh the subscription if the app asks.

Order matters for that last step. A subscription refresh sent while you are still behind the portal cannot reach the server. Happ, for example, documents a "Timeout while adding a subscription" error when the subscription server does not answer within nine seconds. Finish the login first, then retry.

When your own settings keep the login page away

Android: Always-on VPN

Android can keep a VPN permanently on and block all traffic when it is down. On stock Android, both switches are under Settings, Network & internet, VPN, then the gear icon next to the app: Always-on VPN and Block connections without VPN. Other manufacturers put the VPN screen elsewhere, and Samsung, for example, puts it under Connections. With blocking on, the phone may be unable to reach the portal until the VPN is up, and the VPN cannot come up until the portal is done. Turn off blocking for the login, then turn it back on. The rest of the Android setup is in the Android setup guide.

iPhone and iPad: Connect On Demand

Some iOS VPN apps ask the system to reconnect automatically. For configurations that use it, iOS shows a Connect On Demand switch on the VPN's info screen under Settings, General, VPN & Device Management, VPN. Other apps keep an auto-connect option in their own settings. Switch it off, log in, then switch it back on.

Desktop: full-traffic modes and kill switches

Desktop clients that capture all system traffic, often called TUN mode, and kill switches that block traffic outside the tunnel both stop the portal check. The names differ between apps and versions, so look in your client's current settings rather than for a specific label. Pause the mode, log in, and resume.

Encrypted DNS

If the page still refuses to appear with the VPN off, set Android's Private DNS to Automatic and switch off secure DNS in your browser for the login, then restore them.

Private Wi-Fi addresses: why you keep logging in again

Portals usually remember a device by its Wi-Fi hardware (MAC) address. Modern systems use a private address per network, and some rotate it. Each new address looks like a new guest.

  • iPhone and iPad (iOS 18 and later): Settings, Wi-Fi, the info button next to the network, then Private Wi-Fi Address: Off, Fixed or Rotating. Apple says devices choose Rotating by default on open and weakly secured networks, which includes most portals. Choose Fixed for a hotel you are staying at. On a Mac with macOS Sequoia or later, the same menu is under System Settings, Wi-Fi, Details.
  • Android: open the network's settings and look for Privacy, with the options Use randomized MAC and Use device MAC. Samsung calls it MAC address type. Android normally keeps one random address per network, so it is a less frequent cause of repeated logins.
  • Windows 11: in the network's properties under Settings, Network & internet, Wi-Fi, find Random hardware address. Wording varies slightly between Windows builds. The Change daily option means a new login every day, so set it to On or Off for that network instead.

A fixed address lets that one network recognise you across visits. At a hotel that already has your name, it costs little.

Networks that block UDP or unusual ports

WireGuard runs only over UDP, and OpenVPN usually defaults to it. On a network that drops UDP, the handshake never completes. The app sits on "connecting", or it connects and then passes no traffic. Switching to a TCP-based option often helps: OpenVPN over TCP, or protocols built on TCP such as VLESS. The trade-offs are in the protocol comparison.

Kovra, the service that publishes this guide, runs VLESS with REALITY over TCP on every location, so it does not depend on UDP. That is a property, not a promise. A network that allows only a few ports, or filters by destination, can still stop any VPN. If only web ports are open, ask your provider which ports its servers use.

In-flight Wi-Fi

  • Messaging-only tiers recognise a few specific apps and block everything else. A VPN hides which app the traffic belongs to, so it is blocked. You need a browsing tier.
  • Browsing tiers often let VPNs connect. An airline's terms may restrict them, and streaming may be throttled either way.
  • Satellite latency is physical. Links through geostationary satellites add several hundred milliseconds per round trip before the VPN adds its own share. Newer low-orbit services are much faster. Keep expectations for calls and gaming low.
  • The portal rules still apply. Airline portals behave like hotel ones, so the same sequence works.

Quick diagnosis

SymptomLikely causeWhat to do
No login page, nothing loadsVPN or encrypted DNS hiding the portalPause both, open neverssl.com
Login page loops or reappears dailySession limit, or a changing private Wi-Fi addressLog in again; set a fixed address for this network
Logged in, VPN never connectsUDP or ports blockedTry a TCP-based protocol or another location
VPN connected, no pages loadSession expired, or DNS inside the tunnelRe-check the portal, then see connected but no internet
Works in the lobby, not the roomWeak signal or a different access pointLog in again from the room, or use a hotspot

When nothing works

  • Use a phone hotspot or roaming data. It bypasses the venue network entirely, and it is usually the fastest fix.
  • Forget the network and join it again. This often gets you a fresh session and a fresh portal.
  • Try another VPN location. Some networks block specific destinations rather than VPNs in general.
  • Check the date and time. If the clock is far off, HTTPS certificate checks fail, including the app's subscription refresh. Set both to automatic.
  • Ask the front desk. Some hotels run a separate business or premium network, or a wired port, with fewer restrictions.
  • Try again later. Congestion and portal behaviour change through the day.

Some countries add national blocking on top of venue rules. If you are travelling to one, prepare before you leave, as described in the guides to using a VPN in Turkey and what still works in China.

Once you are online

Getting connected is half the job. What an open network can still see, and which settings close those gaps, is covered in public Wi-Fi security. Run the leak test once on a new network to confirm that DNS goes through the tunnel as well.

Frequently asked questions

Why doesn't the hotel Wi-Fi login page appear when my VPN is on?

The login page works by intercepting your first unencrypted web request. A VPN sends that request into an encrypted tunnel instead, and the tunnel cannot open until you have logged in. Pause the VPN, open http://neverssl.com to bring up the login page, finish it, then reconnect.

Is it safe to disconnect the VPN to log in?

The risk during that minute is usually small, because most apps and sites use HTTPS, so their contents stay encrypted without the VPN. Reconnect as soon as the network lets you out. What an open network can still see, and what to avoid while the tunnel is down, is covered in the public Wi-Fi security guide.

Why does my VPN work in the lobby but not in my room?

Rooms are often served by different access points, sometimes on a separate network with its own rules and limits. A weak signal causes packet loss, which makes any tunnel feel broken. Moving between access points can also end your login session. Log in again from the room, move closer to the access point, or ask for a room with better coverage.

Will a VPN work on airplane Wi-Fi?

On a paid browsing tier it often can, though an airline's terms may restrict VPNs. Free messaging-only tiers allow a few specific apps and block everything else, including VPNs. Satellite links add latency, so expect slower page loads than on the ground.

Why does the hotel keep asking me to log in again?

Portals usually remember devices by their Wi-Fi hardware address, and modern phones and laptops use a private address that can change. Sessions also expire after a set time. If a changing address is the cause, setting the private address to fixed for that one network stops the repeated logins; an expired session still needs a new login.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches