VPN Works on Wi-Fi But Not Mobile Data (or the Other Way Round)

By HidVPN Team  ·  September 3, 2026

August 23, 2026

HidVPN guide cover: VPN Works on Wi-Fi But Not Mobile Data 2026

What Each Combination Actually Tells You

If you’re searching because vpn works on wifi but not mobile data, the failed side of the connection gives you a useful diagnosis before you change any settings. The same principle applies in reverse: a failure limited to Wi-Fi points toward the router or ISP, while a failure on one device points toward that device.

Start with free testing. Turn off the VPN, open two ordinary websites, reconnect it, and record whether the app says connecting, connected, or unable to reach the server. A working mobile-data connection is not the same thing as a working VPN tunnel. You need both.

What you observe Most likely cause First action to try
VPN works on Wi-Fi but fails on mobile data Carrier restriction, IPv6 behavior, APN, permissions, or data controls Allow cellular data for the VPN app, disable Data Saver, and test another protocol
VPN works on mobile data but fails on Wi-Fi Router filtering, blocked UDP or port, DNS, ISP interference, or MTU Try another Wi-Fi network and OpenVPN TCP
VPN works on a phone but not a laptop Corrupt profile, desktop firewall, outdated client, or system permission Remove the profile, restart, and reinstall the VPN client
VPN works on a laptop but not a phone Mobile permissions, battery controls, private DNS, or an old mobile profile Update the phone app and permit VPN and cellular access

A VPN can work over mobile data because it creates an encrypted tunnel to a VPN server; your ISP or carrier can see encrypted traffic being sent, but not the contents inside that tunnel. See how VPN encryption and tunneling work for the packet-level explanation.

Based on our research and testing guidance, results can differ by Android or iOS version, carrier, country, protocol, server distance, and network configuration. We recommend changing one variable at a time: record the network, protocol, port, server, and exact error before moving to the next test.

VPN Works on Wi-Fi But Not Mobile Data (or the Other Way Round)

When the VPN Fails on Wi-Fi Only

If vpn works on wifi but not mobile data is not your pattern and the failure occurs only on Wi-Fi, suspect the network before blaming your VPN account. Home routers may block VPN passthrough, filter UDP traffic, force their own DNS, mishandle IPv6 requests, or create an MTU mismatch. Some ISPs also interfere with particular ports or traffic patterns, although the exact behavior varies by country and service.

We found that the fastest test is comparison: try your home Wi-Fi, your phone’s hotspot, and a second trusted Wi-Fi network. If the VPN fails only on the home router, the router or ISP path is the stronger suspect. A troubleshooting test should compare at least three variables—protocol, port, and network—rather than changing several settings together.

  1. Restart the router and phone or laptop, then test again.
  2. Switch from WireGuard or another UDP protocol to OpenVPN TCP.
  3. Try TCP port where the VPN app supports manual port selection.
  4. Inspect the router for VPN passthrough, firewall, parental-control, and traffic-filtering settings.
  5. Temporarily test automatic DNS. Some routers force their own resolver or mishandle DNS over IPv6.

OpenVPN TCP can connect on restrictive networks because TCP traffic on port resembles ordinary encrypted web traffic. It may be slower than WireGuard or another UDP-based protocol because retransmitted packets add overhead; a IETF explanation of TCP transport behavior describes why reliability can involve additional packet exchanges.

Before changing router settings permanently, test automatic DNS and another network. Router MTU changes affect every connected device, so read the provider’s instructions in this VPN router setup guide first. Our recommendation is simple: prove the failure follows the router before editing advanced settings.

When the VPN Fails on Mobile Data Only

When a VPN works on Wi-Fi but not mobile data, the mobile carrier becomes the first place to investigate. Common causes include carrier-level filtering, unstable radio coverage, a restricted APN, Low Data Mode or Data Saver, background-data limits, and an exhausted data cap. Encryption also adds packet overhead, so a VPN connection may use slightly more data than the same traffic without a tunnel.

On Android, open Settings and check that cellular data is enabled for the VPN app, background data is permitted, Data Saver is off for testing, and the app is excluded from aggressive battery optimization. On iOS, check Settings > Cellular and enable the VPN app, then temporarily disable Low Data Mode. Restart the phone and test again in a stronger 4G or 5G location.

IPv6 deserves special attention. Some mobile networks provide IPv6 connectivity through 464XLAT, a translation system documented by the Internet Engineering Task Force. The phone may have no conventional IPv4 address, and an older VPN app, DNS path, or poorly configured VPN server may fail to negotiate correctly. That does not mean every IPv6-heavy network breaks VPNs; it means compatibility should be tested rather than assumed.

  1. Update the VPN app and phone operating system.
  2. Test the provider’s protocol with the strongest published IPv6 support.
  3. Try a nearby VPN server and compare the connection result.
  4. Check whether the provider documents IPv6 compatibility and mobile-network limitations.
  5. Compare the VPN app’s data usage with Android or iOS cellular usage before assuming it consumed your full cap.

Do not randomly edit APN fields. Screenshot the current values, restore the carrier’s default APN or reset network settings, and contact the carrier if ordinary browsing also fails. A US 5G carrier, a European IPv6-heavy network, and a roaming SIM abroad can produce different results because routing, translation, and filtering differ.

NordVPN, Surfshark, ExpressVPN, CyberGhost, and IPVanish all offer Android and iOS apps, but mobile performance is not identical. Compare protocol choices, user-friendly controls, nearby server availability, data behavior, and each provider’s published no-logs policy. If NordVPN is affected, use this NordVPN troubleshooting guide rather than assuming the carrier is at fault.

VPN Works on Wi-Fi But Not Mobile Data (or the Other Way Round)

When the VPN Fails on One Device Only

If the same Wi-Fi and mobile-data connections work on another device, stop changing router and carrier settings. A one-device failure usually involves a corrupted VPN configuration profile, duplicate VPN entries, OS permissions, an outdated app, an incorrect date and time, battery optimization, or another security app intercepting traffic.

Use this repair sequence, which preserves a clear before-and-after comparison:

  1. Update the operating system and VPN app.
  2. Write down the current server and protocol, then remove old VPN profiles and duplicate entries.
  3. Restart the device.
  4. Reinstall the app or add the provider profile again.
  5. Approve the VPN permission prompt and test the provider’s default protocol.

On Android, inspect Always-on VPN, per-app VPN rules, battery optimization, and Private DNS. An Always-on rule from a previous provider can conflict with a new profile, while battery restrictions can stop background tunnel negotiation. On iOS, remove the VPN configuration, check cellular permission and Low Data Mode, then consider Reset Network Settings only after recording Wi-Fi passwords and APN details.

Resetting network settings can remove saved Wi-Fi passwords, cellular settings, and VPN profiles. We tested a scenario where an iPhone worked over both Wi-Fi and mobile data, while an Android phone failed because an old configuration profile and battery restriction prevented negotiation. Removing the profile and allowing background activity restored the connection.

There is also a privacy risk in repeatedly tapping Connect without checking the status bar or app state. If the operating system falls back to an ordinary connection, your traffic may leave without the VPN’s encryption. Confirm the VPN says connected before handling sensitive accounts, especially on unfamiliar networks.

Hotel and Public Wi-Fi: Complete the Captive Portal First

Hotels, airports, cafés, and public Wi-Fi networks often use a captive portal: a browser page asking for a room number, email address, password, or acceptance of terms. Until you complete it, the network may permit only the sign-in redirect. Starting the VPN first can leave the app stuck on connecting because the encrypted tunnel prevents that redirect from appearing.

  1. Connect to the public Wi-Fi.
  2. Turn off the VPN temporarily.
  3. Open a non-sensitive HTTP page or wait for the network sign-in prompt.
  4. Complete the portal and confirm ordinary browsing works.
  5. Reconnect the VPN before signing into banking or entering other sensitive information.

If the page will not load, forget and reconnect to the network, then temporarily disable Private DNS on Android or similar custom DNS settings. Ask the front desk whether the network restricts VPN traffic. A phone hotspot is a useful comparison: if the VPN connects immediately over mobile tethering, the hotel network is probably filtering a protocol or port.

VPN encryption protects traffic between your device and the VPN server; it does not make a fake hotspot trustworthy or protect you from a phishing page. The risks of public Wi-Fi include rogue access points and deceptive login pages, so inspect the address before submitting credentials.

Streaming services may still show a proxy error after the VPN connects. That message means the service detected VPN or proxy traffic; it is different from a tunnel connection failure. Also monitor hotspot data usage: encrypted traffic adds overhead, and a short hotel stay can consume a meaningful share of a capped mobile plan.

MTU: The Fix Nobody Mentions

MTU is the largest packet size a connection can send before the packet must be split. Ethernet commonly uses 1,500 bytes, but a VPN adds encryption headers. A path that handles an ordinary 1,500-byte packet may mishandle the larger encapsulated packet, especially across PPPoE, IPv6 translation, cellular networks, or restrictive routers.

The symptoms are distinctive: the VPN says connected, small pages load, but streaming services, large websites, file transfers, or particular apps hang. This can happen on Wi-Fi, mobile data, or only one carrier path. If changing protocol or network fixes the problem, MTU is less likely; if the tunnel connects but larger traffic fails on one path, MTU becomes a stronger suspect.

  1. Record a baseline speed test and test two ordinary websites.
  2. Change only the VPN or network MTU setting, not several options at once.
  3. Lower it in small steps, such as bytes, then repeat the same tests.
  4. Stop when the behavior improves, and compare speed and reliability.
  5. Restore the original value if no improvement appears.

There is no universal best MTU. The correct value depends on the path and protocol, and a router setting affects every device in the home. Consult your provider’s support documentation before editing it; the IETF’s Path MTU Discovery documentation explains why packet size and fragmentation behavior matter.

In our experience, MTU testing is most useful after you have compared a second network and protocol. It is a targeted diagnosis, not a magic number: lower the value carefully, measure the result, and keep the setting only when the same failure reliably improves.

Key Takeaways

  • Test ordinary internet access before testing the VPN; confirm Wi-Fi or mobile data works with the VPN turned off.
  • If it fails only on mobile data, check carrier restrictions, IPv6, APN settings, permissions, and Data Saver or Low Data Mode.
  • If it fails only on Wi-Fi, check the router, ISP path, DNS, protocol, port, and MTU.
  • If only one device fails, repair its VPN profile and permissions, then reinstall the app and test the default protocol.
  • On hotel or public Wi-Fi, complete the captive portal before reconnecting the VPN.

Next, identify which side fails, change one setting at a time, test on a second network, update the app, and contact the VPN provider or carrier with the exact device, protocol, network, and error message. VPN performance depends on encryption overhead, carrier routing, server distance, protocol support, and local restrictions—not simply on whether you use NordVPN, Surfshark, ExpressVPN, CyberGhost, or IPVanish.

Record the combination that works: network, protocol, server, device, and date. That small log can save time after an OS update, SIM change, or trip abroad. The fastest diagnosis is rarely a reinstall first; it is finding which side of the connection changed.

Frequently Asked Questions

Why does my VPN not work with mobile data?

When a VPN works on Wi-Fi but not mobile data, the likely causes include carrier restrictions, IPv6 behavior, APN settings, Data Saver or Low Data Mode, and cellular permissions. First confirm that ordinary websites load with the VPN turned off, then test another VPN protocol and a stronger mobile signal.

Why does my VPN only work on Wi-Fi?

A VPN may work on mobile data but fail on Wi-Fi because the router or ISP blocks UDP traffic, VPN passthrough, particular ports, DNS requests, or larger encrypted packets. Try another Wi-Fi network, then test OpenVPN TCP and TCP port if your provider supports it.

How do I make a VPN work with mobile data?

Turn off the VPN and confirm that mobile browsing works. Then allow the VPN app to use cellular data, disable Data Saver or Low Data Mode temporarily, update the app, try another protocol, and test near a stronger 4G or 5G signal.

Does a VPN work when using mobile data?

Yes, a VPN can work over mobile data. It encrypts traffic between your device and a VPN server, but carrier routing, APN settings, IPv6-only connectivity, data limits, and phone permissions can affect whether the tunnel connects.

Why does my VPN work on my phone but not my laptop?

A VPN that works on a phone but not a laptop usually indicates a laptop-side issue, such as an old VPN profile, blocked permission, incorrect date and time, security software, or an outdated app. Remove the existing profile, restart the laptop, reinstall the app, and test its default protocol.

HidVPN at a Glance
17
VPNs Reviewed
100%
Independent Testing
2026
Data Refreshed
Not sure which VPN?
Answer 4 quick questions and get a match.
Take the Quiz