Why does my VPN not work on hotel, campus or office Wi-Fi?

Updated

Many guest and managed Wi-Fi networks block VPNs by recognising the protocol's handshake or by closing every port except web traffic (80 and 443). WireGuard and OpenVPN are easy to spot. A protocol that looks like ordinary HTTPS on port 443, such as VLESS with Reality, usually still connects, as long as the network permits it.

A man on a phone call working on a laptop in a hotel room
Photo: Vitaly Gariev on Unsplash

You join the hotel Wi-Fi, accept the terms on the login page, open your VPN app and it spins on "Connecting…" forever. Websites load fine without the VPN. This is one of the most common VPN problems, and it is rarely a fault of your phone or of the VPN server. The network in between is filtering the connection.

This guide explains what such a network actually blocks, how to find out which case you are in, and what to switch on Android so you can connect again.

The short version

What you seeMost likely causeWhat usually helps
VPN never connects; websites work without itThe network recognises and drops the VPN handshake (deep packet inspection)A protocol that looks like HTTPS: VLESS with Reality, on port 443
VPN never connects; even some apps fail without itOnly ports 80 and 443 are openAny VPN mode that runs on TCP 443
Connects, then drops after a few secondsUDP is throttled or cut after the first packetsSwitch from WireGuard (UDP) to a TCP-based mode
Nothing works, not even websitesYou have not finished the Wi-Fi login page (captive portal)Turn the VPN off, open any website, accept the terms, then reconnect
Works on mobile data, fails on one Wi-Fi onlyThat network's policyCheck the rules first; if VPNs are allowed, try the HTTPS-like mode

Why do some Wi-Fi networks block VPNs?

Hotels, airports, trains, universities and offices run their networks with a firewall in front. The reasons are mostly mundane: saving bandwidth, keeping guests from running torrents, or company security rules that require all traffic to pass an inspection proxy. Blocking VPNs is a side effect of those rules, or sometimes an explicit policy.

There are three common techniques:

  • Port blocking. The firewall only allows web ports (80 for HTTP, 443 for HTTPS) and DNS. WireGuard's default UDP port 51820 and OpenVPN's 1194 are simply closed.
  • Protocol fingerprinting (DPI). Deep packet inspection looks at the first packets of a connection. The WireGuard handshake has a fixed size and structure, and OpenVPN has a recognisable header, so a firewall can identify them on any port and drop them.
  • UDP throttling. Some networks let UDP through but slow it down or cut long sessions. WireGuard runs only over UDP, so it suffers first.

How do I find out what my network is blocking?

You can narrow it down in two minutes on Android:

  1. Rule out the login page. Turn the VPN off and open http://neverssl.com in the browser. If a hotel or campus login page appears, accept it, then try the VPN again. Most "VPN not working" cases end here.
  2. Compare with mobile data. Switch Wi-Fi off and connect over mobile data. If the VPN connects instantly, the problem is the Wi-Fi network, not the app or the server.
  3. Try a TCP mode on port 443. If your app lets you choose the protocol, switch from WireGuard to a mode that runs over TCP 443. If that connects, the network was blocking UDP or the WireGuard fingerprint.
  4. Check the time and date. A phone clock that is far off breaks encrypted handshakes. Set it to automatic.

Which VPN protocol works best on restrictive Wi-Fi?

The protocol matters more than the server location. Here is how the common ones behave on a filtered network:

ProtocolTransportDefault portHow easy to detectSpeed
WireGuardUDP51820 (any)Easy: fixed handshake patternFastest
OpenVPNUDP or TCP1194 (any)Easy: recognisable headerMedium
IKEv2 / IPsecUDP500, 4500Easy: standard ports, often closedFast
VLESS with RealityTCP443Hard: the handshake is a real TLS handshake to a well-known siteFast

What is Reality? Reality is a transport from the Xray project. When your phone connects, the handshake is a genuine TLS 1.3 handshake that presents the certificate of a real, popular website. To a firewall it looks like a normal visit to that site on port 443. Only a client holding the right key gets a VPN tunnel. Everyone else is passed through to the real website. That is why it keeps working on networks that block WireGuard and OpenVPN.

WireGuard is still the better choice when the network allows it: it is simpler and slightly faster. The practical setup is to use WireGuard by default and fall back to Reality only when WireGuard cannot connect.

Is it OK to use a VPN on school or work Wi-Fi?

That depends on the network's rules, and you should respect them. Many employers require company traffic to pass their own security tools, and some schools forbid VPNs in their acceptable-use policy. If a network blocks VPNs on purpose and you have agreed to its terms, ask the administrator, or use mobile data for private browsing instead.

On hotel, café, airport and train Wi-Fi the situation is different: the network is shared with strangers, the operator does not need to see what you do, and a VPN is a reasonable way to keep your traffic private. VPN blocks there are usually a side effect of a generic firewall preset, not a policy aimed at you.

How SimpleV handles restrictive networks

SimpleV VPN for Android ships both protocols and picks between them for you:

  • Auto mode tries WireGuard first and switches to VLESS with Reality on TCP 443 when WireGuard cannot get through.
  • You can also pin one protocol in the settings if you already know the network.
  • Both protocols are available on the free plan: 500 MB of data every day, no account or email needed.
  • Premium removes the daily limit and unlocks 33 locations in 20 countries on up to 5 devices. A 7-day pass that does not renew is handy for a single trip.

FAQ

Why does my VPN connect on mobile data but not on Wi-Fi?

Because the Wi-Fi network filters VPN traffic and your mobile carrier does not. The phone and the VPN server are fine. Try a protocol that runs over TCP 443 and looks like HTTPS, such as VLESS with Reality, or finish the Wi-Fi login page first if there is one.

Will changing the VPN server location fix a blocked Wi-Fi?

Usually not. The firewall blocks the protocol or the port, not a particular country. Changing the protocol (for example from WireGuard to Reality on port 443) is what makes the difference.

Is VLESS Reality slower than WireGuard?

Slightly, because it runs over TCP and adds TLS framing. On a typical hotel or office connection the difference is hard to notice, and a working connection is faster than one that never connects.

Can a network tell that I am using Reality?

It sees an encrypted connection on port 443 to what looks like a well-known website, which is what most of its traffic looks like. Very strict networks can still block all unknown destinations, so no protocol can promise to work everywhere.

Do I need a paid VPN for this?

No. In SimpleV both WireGuard and Reality work on the free plan, with 500 MB of data a day. Premium adds unlimited data, every location and up to 5 devices.