When a VPN keeps disconnecting, repeatedly pressing Connect is rarely the real solution. A drop can come from an unstable Wi-Fi or mobile network, a sleep or battery-saving policy, a protocol that does not fit the current network, conflicting proxy settings, an outdated subscription, or a route that is temporarily difficult to use. The same symptom can therefore require a different fix on Windows, macOS, Android, iOS, or Linux.

This guide uses a platform-by-platform troubleshooting order. Start with the boundary of the failure: does the internet itself disappear, does only the VPN tunnel close, or does the client remain connected while websites stop loading? Then change one variable at a time. If you switch protocol, route, client, and DNS simultaneously, you may restore service without learning what caused the failure.

1. Identify what is actually disconnecting

Begin by observing the exact sequence rather than relying on the notification alone. If every website stops loading at the same moment that the VPN icon disappears, the tunnel may have closed. If the VPN icon remains active but pages time out, the issue may be DNS resolution, a dead route, a proxy conflict, or an application-specific rule. If the device itself changes from Wi-Fi to mobile data, the handover may have interrupted the tunnel even though both networks work normally on their own.

Test the local connection with the VPN disabled. Open more than one ordinary website or use another network if available. You do not need to measure an exact speed value to establish the basic distinction: if the connection is unstable without the VPN, repair the network before tuning the VPN. On a mobile device, moving between a weak indoor Wi-Fi signal and cellular data can cause short interruptions that are long enough to terminate some tunnels.

Next, note whether the problem appears after the screen turns off, when the computer wakes from sleep, after changing networks, or only with one particular node. Timing is useful evidence. A drop after screen lock points toward background restrictions; a drop after sleep points toward the operating system or network adapter; a drop on one route points toward that route or its protocol; a drop immediately after importing a configuration points toward the profile or client.

5

Supported platform families

90+

Countries covered

200+

Available routes

Unlimited

Simultaneous devices

Check the event pattern

Use a short written record while troubleshooting: device and operating system, network type, client name, selected protocol, selected route, and the event that preceded the drop. This is more useful than repeatedly reconnecting without a record. Do not post a subscription link in a public support channel or screenshot it with the full token visible. A subscription link is configuration access and should be treated as sensitive.

  • ✅ Confirm whether ordinary internet access works with the VPN disabled
  • ✅ Test a second network when the first one appears unstable
  • ✅ Check whether drops follow screen lock, sleep, or network changes
  • ❌ Do not change several protocols and clients at the same time

2. Apply the seven fixes in the right order

Fix 1: Stabilize the underlying network

Reconnect to Wi-Fi, restart the local router if that is appropriate for your environment, or temporarily test cellular data. On a computer, check whether the Wi-Fi adapter is repeatedly roaming between access points. Captive portals in hotels, schools, offices, and cafés can also interrupt VPN setup until you complete the network’s sign-in page. Connect to the local network, complete any required browser login, and only then start the VPN.

When moving from Wi-Fi to mobile data, allow the device to finish the handover before reconnecting. Some clients can survive a network change, while others need a manual reconnect. A stable VPN cannot be built on a constantly changing or restricted local link.

Fix 2: Remove battery and background restrictions

Android is especially likely to suspend a VPN app or its background service when battery optimization is aggressive. Open the system settings for the VPN client and allow background activity where the device provides that option. Disable task-killer, memory-cleaner, or automatic app-freezing features for the client. Also check whether a manufacturer-specific power mode is closing background apps after the screen is locked.

On iOS, the available controls differ from Android, but Low Power Mode, network changes, and app suspension can still affect the continuity of a tunnel. Keep the official client updated, check its VPN or on-demand settings, and test whether the drop occurs only after the device has been idle. Do not assume that leaving an app open in the app switcher guarantees that its network extension will remain active.

Fix 3: Change the protocol deliberately

A protocol is not a magic “fast mode”; it defines how the tunnel is established, authenticated, encrypted, and transported. WireGuard is lightweight and often reconnects quickly, but its behavior still depends on the client and network. OpenVPN is widely supported and can be useful when compatibility matters. Trojan, VMess, Shadowsocks, and Hysteria2 belong to different proxy or transport ecosystems and should be used only when the selected client and imported configuration support them correctly.

Change only the protocol first, keep the route constant, and observe whether the symptom changes. If the client offers automatic selection, use it as a starting point, not as proof that every protocol is available on every route. A profile made for sing-box may not map directly to a third-party client with a different configuration format. Similarly, a Clash Verge profile, a Shadowrocket subscription, and an official client subscription may expose different import options.

Fix 4: Try another route or region

A single node can be temporarily congested, undergoing maintenance, or poorly matched to the current network. Try another route in the same general region before making a large configuration change. If several routes in one region fail while routes elsewhere connect, the pattern points toward regional availability or network treatment rather than a damaged device.

Route names may indicate different capacities or transport designs, but a label alone does not prove that one entry is always best. Test the route with the application you actually need, and keep local services outside the tunnel when split routing is available and appropriate. For streaming, gaming, work tools, and ordinary browsing, the best choice can differ because they create different traffic patterns and react differently to packet loss.

Fix 5: Refresh the subscription or profile

If a subscription update fails, the client may keep using an old or incomplete list. Copy the subscription link from the user panel again, remove accidental spaces, and update the subscription inside the client rather than pasting it into a public browser or chat. Confirm that the account and plan are active in the panel. A successful account login does not automatically mean that a third-party client has refreshed its route data.

For Clash Verge or sing-box, verify that the profile format matches the client and that the intended proxy group is selected after the update. For Shadowrocket, confirm that the subscription was added under the correct subscription area and that a usable node is selected. For an official Windows, macOS, Android, iOS, or Linux client, use the application’s own account or subscription entry and avoid importing an unrelated format unless the product documentation explicitly supports it.

Fix 6: Remove proxy and VPN conflicts

Only one network tool should normally control the system proxy path at a time. Close other VPN applications, proxy clients, traffic filters, DNS switchers, and security tools that may install their own virtual adapter or system proxy. Running an official client beside Clash Verge, sing-box, or Shadowrocket on the same device can create competing routes, port conflicts, or repeated handoffs.

On desktop systems, check the operating system’s manual proxy setting after closing the old client. On Windows, also inspect virtual network adapters if an old installation left one behind. On macOS and Linux, review system proxy variables and network-manager profiles where applicable. Do not delete adapters or configuration files blindly; first record the current settings so that you can restore them if the VPN is not the cause.

Fix 7: Update, reset, and reinstall last

Update the operating system and VPN client through trusted distribution channels. A client may lose stability after an operating system update if its network extension, permission, or virtual adapter is no longer accepted. Reboot after an update when the client documentation requests it. If the problem persists, export or record the configuration you are allowed to keep, remove the affected profile, and import a fresh copy.

Reinstalling should be the final step, not the first reaction. It can clear damaged local state, but it will not fix an unstable access network, a route problem, or an incorrect protocol. After reinstalling, test with one clean profile and one route before restoring every custom rule.

One-line conclusion: Diagnose the layer first, then change network, background policy, protocol, route, profile, conflict, and installation in that order.

3. A hands-on recovery procedure

Use the following controlled procedure when you need a reliable answer rather than another temporary reconnect. It works with an official client and can be adapted to compatible clients such as Clash Verge, sing-box, and Shadowrocket. The menu names vary, but the logic remains the same.

  1. Disconnect cleanly. Turn off the VPN from the active client and wait for the operating system to show ordinary network access. Close other VPN or proxy clients so that only one tool remains under test.
  2. Verify the local link. Open a normal website without the VPN. If the page does not load consistently, fix Wi-Fi, mobile data, captive portal, or DNS problems before continuing.
  3. Check the account and plan. Sign in to the panel with the username and password. No email address is required for registration. Confirm that the subscription or download entry is visible and that you are using the current account.
  4. Refresh one profile. Copy the subscription link again and update it in the client. Do not combine this step with a protocol change. Select one newly listed route.
  5. Connect with the default or recommended protocol. Wait for the client to report a connected state, then test the target application. If it drops, record the timing instead of immediately switching everything.
  6. Change one variable. Keep the profile and route fixed while trying another supported protocol. If the protocol change does not help, restore it and try another route instead.
  7. Repeat after a screen lock or sleep test. If the tunnel fails only in the background, adjust battery, background activity, on-demand VPN, or sleep settings for the relevant platform.

For Linux, pay particular attention to the service manager, NetworkManager, environment variables, and any user-level proxy configuration. A terminal client and a desktop client can both be active without an obvious window showing the conflict. For Windows and macOS, check whether a security product is filtering the virtual adapter. For Android and iOS, check permissions and background behavior before assuming that the server is unavailable.

Observed behavior Most likely area First action
VPN drops when Wi-Fi changes Network handover or local link Reconnect after the new network is stable
VPN drops after the screen locks Background or battery policy Allow background activity for the client
Only one route repeatedly fails Route availability or capacity Try another route with the same protocol
Client connects but apps cannot load DNS, rules, or proxy conflict Disable competing tools and review split-routing rules
Every imported route is missing Subscription or format issue Refresh the link and confirm client compatibility

4. Platform-specific checks

Windows

On Windows, inspect the VPN client’s connection mode, virtual adapter, and system proxy behavior. If the client uses a TUN adapter, confirm that another application has not already claimed the same traffic path. If it uses a system proxy, check Windows proxy settings after closing the client and remove stale manual entries only when you know they belong to the old configuration. Security software may also inspect or block the virtual adapter, so temporarily test with the relevant network protection setting reviewed according to your organization’s policy.

macOS

macOS may request approval for a VPN configuration or network extension. If that permission was denied, incomplete, or invalidated by an update, the client can appear installed while the tunnel fails. Review VPN and network-extension entries in system settings, and remove only profiles you recognize. If the Mac wakes from sleep into a broken tunnel, disconnect and reconnect after the network icon shows a stable connection.

Android

Android troubleshooting should begin with battery optimization, background data, and manufacturer task-management settings. Allow the VPN client to run in the background and check whether a “sleeping apps” list includes it. Review Always-on VPN or “block connections without VPN” settings carefully: these can improve leak protection, but an incorrect configuration may make all traffic appear offline when the tunnel is down. Change one setting, test, and then restore the protection you need.

iOS

On iOS, confirm that the VPN configuration is present and that the client has permission to create or manage it. Check Low Power Mode and on-demand behavior when drops happen during idle periods. If you use Shadowrocket, make sure the correct configuration is active and that the selected rule mode is intentional. If you use an official client, update its subscription or account entry inside that app rather than mixing it with a separate proxy profile.

Linux

Linux installations vary more than other platforms. A WireGuard interface, an OpenVPN service, a sing-box process, and a desktop network manager can all affect routing independently. Review active interfaces, routes, DNS settings, and service status using the tools appropriate to your distribution. Stop duplicate services before testing. If a configuration was copied from another client, verify its syntax and transport support instead of assuming that a valid-looking file is compatible with every implementation.

  • ✅ Use the official client when you want the simplest account and subscription workflow
  • ✅ Use Clash Verge, sing-box, or Shadowrocket only with a format and protocol they support
  • ✅ Keep one client active during diagnosis
  • ❌ Do not treat a connected icon as proof that every application is using the tunnel
  • ❌ Do not delete system VPN profiles without recording what they control

5. When the problem needs support

Contact support after you have identified a repeatable pattern. A useful report includes the platform, operating system version, client name and version, whether you used an official client or a compatible third-party client, the protocol, the route or region, and whether ordinary internet access worked at the time of failure. Explain what changed immediately before the drop and whether the failure happens in the foreground, in the background, after sleep, or only on one application.

Never include your account password or expose the complete subscription link in a public message. If support requests diagnostic information, follow the service’s secure submission method and remove unrelated personal data from logs where possible. A precise report helps distinguish a client permission issue from a route issue and avoids unnecessary resets.

Also review the service’s platform coverage before changing clients. VPN TX supports Windows, macOS, iOS, Android, and Linux, with official client and subscription workflows alongside compatible-client options where applicable. Route availability can vary by protocol and client, so the practical question is not simply whether a node appears in a list; it is whether the selected client can parse the profile, establish the tunnel, and pass traffic consistently on your current network.

Best troubleshooting habit: Keep a known-good baseline—one client, one refreshed profile, one protocol, and one route—then add custom rules only after the baseline remains stable.

Frequently asked questions

Why does my VPN disconnect when my phone screen turns off?

Battery optimization, background restrictions, low-power modes, and manufacturer task management are common causes. Allow the VPN client to operate in the background, review Always-on VPN settings, and test again after locking the screen. If the local network also changes during that period, troubleshoot the network handover separately.

Should I change the protocol every time the VPN drops?

No. First confirm that ordinary internet access is stable and that the profile is current. Then change one supported protocol while keeping the route constant. WireGuard and OpenVPN are common choices with different compatibility and transport behavior; Trojan, VMess, Shadowsocks, and Hysteria2 require a client and profile that explicitly support them.

Can I run an official client and Clash Verge or sing-box together?

You can install several clients, but running multiple traffic controllers at the same time often creates proxy, port, adapter, or routing conflicts. During diagnosis, close all but one client. After stability is confirmed, use only the tool whose rules and protocol support match your intended setup.

Will reinstalling the app fix frequent disconnections?

It can clear corrupted local state or a damaged network extension, but it cannot repair an unstable Wi-Fi connection, a battery policy, an unsuitable route, or an outdated subscription. Reinstall only after checking those causes, then test the fresh installation with a single clean profile before restoring custom settings.