The pattern is familiar. You join the hotel Wi-Fi, the VPN spins on "connecting", and nothing loads. Often the VPN is not being blocked at all. The network simply has not let you out yet, and the VPN is hiding the page that would. Here is what is going on and the order in which to fix it.
Why these networks break VPNs
Captive portals
A captive portal holds every new device at a login or terms page until you complete it. Your phone or laptop detects this by requesting a known plain-HTTP address from Apple, Google or Microsoft and checking whether the answer has been tampered with. If it has, the system opens the sign-in sheet. Depending on the system and the app, a VPN that captures all traffic can send that check, or the login page itself, into a tunnel which cannot open, so the sheet never appears or never loads.
DNS interception
Many portals answer every DNS lookup with their own address until you log in. Encrypted DNS can bypass that trick. Examples include Android's Private DNS set to a specific provider, secure DNS in Chrome and DNS over HTTPS in Firefox. Android and the browsers try to detect portals and step aside, but when that fails, the redirect never happens.
Port and UDP restrictions
Guest networks are often configured for web browsing and little else. Some block UDP apart from DNS, and some allow only a handful of ports. Both break common VPN setups even after you have logged in.
Client isolation and time limits
Client isolation stops guests from seeing each other's devices. That is good for security, but it is why casting to the room TV can fail, and it is not a VPN problem. Sessions are often time-limited or capped per room. When a session expires mid-stay, the portal silently returns and the VPN looks as if it has died.
The portal-first sequence
- Pause the VPN. Disconnect or pause it, and temporarily turn off any setting that blocks traffic when the VPN is down (see the next section).
- Join the network and wait a few seconds for the sign-in page.
- If nothing appears, open the page yourself. In a browser, go to
http://neverssl.comorhttp://captive.apple.com. Both are deliberately plain HTTP, so the portal can intercept them. An HTTPS site cannot be redirected without a certificate warning. - Complete the login. Enter the room number, surname or voucher code, and accept the terms. Enter no more than the portal genuinely needs.
- Confirm the connection is real. Load an ordinary website you have not opened recently. If it loads, the network is letting you out.
- Reconnect the VPN. Re-enable any blocking setting you paused, and refresh the subscription if the app asks.
Order matters for that last step. A subscription refresh sent while you are still behind the portal cannot reach the server. Happ, for example, documents a "Timeout while adding a subscription" error when the subscription server does not answer within nine seconds. Finish the login first, then retry.
When your own settings keep the login page away
Android: Always-on VPN
Android can keep a VPN permanently on and block all traffic when it is down. On stock Android, both switches are under Settings, Network & internet, VPN, then the gear icon next to the app: Always-on VPN and Block connections without VPN. Other manufacturers put the VPN screen elsewhere, and Samsung, for example, puts it under Connections. With blocking on, the phone may be unable to reach the portal until the VPN is up, and the VPN cannot come up until the portal is done. Turn off blocking for the login, then turn it back on. The rest of the Android setup is in the Android setup guide.
iPhone and iPad: Connect On Demand
Some iOS VPN apps ask the system to reconnect automatically. For configurations that use it, iOS shows a Connect On Demand switch on the VPN's info screen under Settings, General, VPN & Device Management, VPN. Other apps keep an auto-connect option in their own settings. Switch it off, log in, then switch it back on.
Desktop: full-traffic modes and kill switches
Desktop clients that capture all system traffic, often called TUN mode, and kill switches that block traffic outside the tunnel both stop the portal check. The names differ between apps and versions, so look in your client's current settings rather than for a specific label. Pause the mode, log in, and resume.
Encrypted DNS
If the page still refuses to appear with the VPN off, set Android's Private DNS to Automatic and switch off secure DNS in your browser for the login, then restore them.
Private Wi-Fi addresses: why you keep logging in again
Portals usually remember a device by its Wi-Fi hardware (MAC) address. Modern systems use a private address per network, and some rotate it. Each new address looks like a new guest.
- iPhone and iPad (iOS 18 and later): Settings, Wi-Fi, the info button next to the network, then Private Wi-Fi Address: Off, Fixed or Rotating. Apple says devices choose Rotating by default on open and weakly secured networks, which includes most portals. Choose Fixed for a hotel you are staying at. On a Mac with macOS Sequoia or later, the same menu is under System Settings, Wi-Fi, Details.
- Android: open the network's settings and look for Privacy, with the options Use randomized MAC and Use device MAC. Samsung calls it MAC address type. Android normally keeps one random address per network, so it is a less frequent cause of repeated logins.
- Windows 11: in the network's properties under Settings, Network & internet, Wi-Fi, find Random hardware address. Wording varies slightly between Windows builds. The Change daily option means a new login every day, so set it to On or Off for that network instead.
A fixed address lets that one network recognise you across visits. At a hotel that already has your name, it costs little.
Networks that block UDP or unusual ports
WireGuard runs only over UDP, and OpenVPN usually defaults to it. On a network that drops UDP, the handshake never completes. The app sits on "connecting", or it connects and then passes no traffic. Switching to a TCP-based option often helps: OpenVPN over TCP, or protocols built on TCP such as VLESS. The trade-offs are in the protocol comparison.
Kovra, the service that publishes this guide, runs VLESS with REALITY over TCP on every location, so it does not depend on UDP. That is a property, not a promise. A network that allows only a few ports, or filters by destination, can still stop any VPN. If only web ports are open, ask your provider which ports its servers use.
In-flight Wi-Fi
- Messaging-only tiers recognise a few specific apps and block everything else. A VPN hides which app the traffic belongs to, so it is blocked. You need a browsing tier.
- Browsing tiers often let VPNs connect. An airline's terms may restrict them, and streaming may be throttled either way.
- Satellite latency is physical. Links through geostationary satellites add several hundred milliseconds per round trip before the VPN adds its own share. Newer low-orbit services are much faster. Keep expectations for calls and gaming low.
- The portal rules still apply. Airline portals behave like hotel ones, so the same sequence works.
Quick diagnosis
| Symptom | Likely cause | What to do |
|---|---|---|
| No login page, nothing loads | VPN or encrypted DNS hiding the portal | Pause both, open neverssl.com |
| Login page loops or reappears daily | Session limit, or a changing private Wi-Fi address | Log in again; set a fixed address for this network |
| Logged in, VPN never connects | UDP or ports blocked | Try a TCP-based protocol or another location |
| VPN connected, no pages load | Session expired, or DNS inside the tunnel | Re-check the portal, then see connected but no internet |
| Works in the lobby, not the room | Weak signal or a different access point | Log in again from the room, or use a hotspot |
When nothing works
- Use a phone hotspot or roaming data. It bypasses the venue network entirely, and it is usually the fastest fix.
- Forget the network and join it again. This often gets you a fresh session and a fresh portal.
- Try another VPN location. Some networks block specific destinations rather than VPNs in general.
- Check the date and time. If the clock is far off, HTTPS certificate checks fail, including the app's subscription refresh. Set both to automatic.
- Ask the front desk. Some hotels run a separate business or premium network, or a wired port, with fewer restrictions.
- Try again later. Congestion and portal behaviour change through the day.
Some countries add national blocking on top of venue rules. If you are travelling to one, prepare before you leave, as described in the guides to using a VPN in Turkey and what still works in China.
Once you are online
Getting connected is half the job. What an open network can still see, and which settings close those gaps, is covered in public Wi-Fi security. Run the leak test once on a new network to confirm that DNS goes through the tunnel as well.