Full Diagnostic Tree & Step-by-Step Overview
First, disconnect your VPN completely. Can your computer or mobile device access standard websites over your normal internet connection?
- Yes, standard internet works fine, but turning ON the VPN causes a specific error code or infinite loading screen
- No, internet is broken on my device EVEN WHEN the VPN is turned off
- The VPN connects successfully, but NO WEBSITES LOAD (Connected with No Internet Access)
What specific symptom or Windows/VPN error code is displayed when the connection fails?
- Windows Error 807, 800, or OpenVPN 'TLS Key Negotiation Failed / Handshake Timeout'
- Windows Error 720 ('A connection to the remote computer could not be established')
- Windows Error 691 or 'Authentication Failed / Invalid Credentials'
- VPN client hangs indefinitely at 'Connecting...' or 'Assigning IP Address'
Locked Firewall Rules Left Behind by Crashed VPN Kill-Switch
Solution:
Diagnostic Cause
Modern VPN clients use a 'Kill-Switch' feature that modifies system firewall rules to block all unencrypted traffic outside the tunnel. If the VPN app crashes or terminates abruptly, these drop-all firewall rules remain active in the OS, severing normal internet connectivity.
Step-by-Step Fix
1. Launch your VPN application > navigate to Settings > Security.
2. Manually toggle Kill Switch to OFF.
3. Fully close the VPN client (ensure its background task is ended in Task Manager / Activity Monitor).
4. Open Command Prompt as Administrator (Win + X > *Terminal/CMD (Admin)*).
5. Execute these commands to flush leftover route bindings and reset firewall defaults:
netsh advfirewall reset *(Restores default Windows Firewall rules)*ipconfig /flushdns *(Purges OS DNS lookup table)*netsh winsock reset *(Clears socket state)*6. Reboot your computer. Standard internet access should now function without the VPN.
VPN Connected but DNS Lookup Routing Interrupted
Solution:
Diagnostic Cause
The VPN tunnel successfully builds, but your operating system continues attempting to route DNS requests to your local router gateway instead of through the secure VPN tunnel DNS interface.
Step-by-Step Fix
1. In your VPN client settings, look for DNS Settings or Custom DNS.
2. Switch DNS mode from 'System Default' to the VPN Provider's Default DNS or force high-reliability resolvers:
Set Primary DNS: 1.1.1.1Set Secondary DNS: 8.8.8.83. Open Command Prompt (Admin) and run ipconfig /flushdns.
4. Open ncpa.cpl (Win + R), right-click your physical Ethernet/Wi-Fi adapter > select Properties.
5. Double-click Internet Protocol Version 4 (TCP/IPv4) > click Advanced.
6. On the IP Settings tab, ensure Use default gateway on remote network is checked under your VPN adapter settings if using standard OS VPN clients.
Error 807 / 800 / TLS Handshake Timeout (Network Firewall Dropping Packets)
Solution:
Diagnostic Cause
Error 807/800 or TLS Handshake Timeouts occur when intermediate network devices (ISPs, public Wi-Fi routers, corporate firewalls) inspect and drop VPN tunnel handshake packets sent via standard UDP ports (e.g., OpenVPN UDP 1194 or IPsec UDP 500/4500).
Step-by-Step Fix
1. Open your VPN app settings > navigate to Protocol / Connection.
2. Change the protocol from *OpenVPN UDP* or *IKEv2* to WireGuard or OpenVPN TCP.
3. If using OpenVPN TCP, set the remote port to 443 (This wraps your VPN traffic inside standard HTTPS/SSL port 443, making it nearly impossible for basic firewalls to block).
4. If using a home router, access its admin portal (192.168.1.1) and enable IPsec Passthrough, PPTP Passthrough, and L2TP Passthrough under *Security/Firewall settings*.
5. Temporarily disable third-party Antivirus 'Web Shield' or 'Firewall' modules to check if they are intercepting outbound UDP handshake packets.
Error 720 (Corrupted PPP Control Protocol or WAN Miniport Drivers)
Solution:
Diagnostic Cause
Windows Error 720 indicates that the system's internal WAN Miniport network interfaces (IP, IPv6, PPTP, L2TP) or PPP control protocol stacks have become corrupted inside the Windows Registry.
Step-by-Step Fix
1. Press Win + X > select Device Manager.
2. Expand Network adapters.
3. Locate and right-click all WAN Miniport devices (e.g., *WAN Miniport (IP)*, *WAN Miniport (IPv6)*, *WAN Miniport (PPTP)*) and select Uninstall device for each.
4. Don't panic: these are built-in virtual drivers. Once uninstalled, click Action on the top Device Manager menu bar > select Scan for hardware changes.
5. Windows will automatically detect and rebuild fresh, uncorrupted WAN Miniport drivers.
6. Open CMD as Admin and execute netsh int ip reset c:\resetlog.txt then restart your computer.
Error 691 / Authentication Failure (Token Mismatch or Drift)
Solution:
Diagnostic Cause
Error 691 occurs when the remote VPN server rejects authentication credentials. This is frequently caused by expired local OAuth tokens, mismatched client manual credentials, or system clock drift breaking time-based TOTP/RADIUS tokens.
Step-by-Step Fix
1. Log completely out of your VPN desktop/mobile app and log back in to clear saved local session tokens.
2. Verify system clock synchronization:
Windows: Settings > *Time & Language* > *Date & time* > Click Sync now under *Additional settings*.macOS: System Settings > *General* > *Date & Time* > Ensure *Set time and date automatically* is toggled ON.3. If using manual OpenVPN or Router configurations, ensure you are using your VPN provider's Service Credentials/Manual Configuration Keys, NOT your main account password.
Virtual Adapter Initialization Failure ('Connecting...' Infinite Loop)
Solution:
Diagnostic Cause
VPN clients rely on virtual software adapters (such as *TAP-Windows Adapter V9*, *Wintun*, or *WireGuard Tunnel Driver*) to encapsulate packets. If another software update or secondary VPN corrupts this virtual interface, the client stalls indefinitely while waiting for the adapter to report an 'Up' state.
Step-by-Step Fix
1. Open Device Manager (Win + X > *Device Manager*).
2. Expand Network adapters.
3. Look for TAP-Windows Adapter V9, NordVPN TAP, ExpressVPN TAP, or Wintun Userspace Tunnel.
4. Right-click the virtual adapter > select Uninstall device > check Attempt to remove the driver for this device > click Uninstall.
5. Open your VPN app setup folder (or download the latest installer from your provider) and run the installer in Repair or Reinstall mode.
6. This cleanly deploys a new TAP/TUN NDIS driver instance with full registry bindings.