Wi-Fi bars are full, 5G is active, the VPN key sits quietly in your status bar, and your VPN app proudly reports “Connected.” Yet Chrome spins indefinitely, notifications stall, and messages refuse to send.
These facts do not contradict each other. On Android, an active VPN service and a usable data path are not the same thing. Android can dutifully keep a VPN process alive while nothing of value travels through it.
When this happens, the instinct is usually to panic-tweak: cycle through random servers, reboot the phone, toggle airplane mode, and permanently turn off Android’s lockdown security. Don't do that. Changing five variables at once teaches you nothing, leaves your device unprotected, and ensures the glitch will return the next time you walk out the door.
Instead of asking whether the VPN is connected, ask what still works. The specific boundary where your connection fails tells you exactly what is broken.
Article summary and product fit
What this article answers
On Android, “Connected” can mean the VPN process is alive even when no usable route exists. Diagnose the failure by the boundary that breaks: the base network, the VPN route, one app or work profile, or the Wi-Fi-to-cellular handoff.
Key points and limits
- Best for: Android users running Always-On VPN with Block connections without VPN who see a VPN key icon but cannot load pages or send data.
- Key point: Temporarily relaxing lockdown is a diagnostic control: if the base internet works immediately, the failure is inside the VPN path rather than the Wi-Fi or carrier itself.
- Limit: Do not leave lockdown disabled as a permanent workaround, and do not try to bypass employer-enforced work-profile policy or an unsigned captive portal.
- Product fit: OnlydogVPN fits the article’s handoff-recovery case when Android moves between otherwise viable networks; it does not replace captive-portal login or restore a dead carrier connection.
Sources used in this article: Android Always-On VPN guidance; Google Android connectivity guidance; Android Enterprise VPN policy; Android Private DNS guidance.
Stop Asking Whether the VPN Is “Connected”
Android separates VPN management into two distinct controls:
- Always-On VPN: Android keeps the chosen VPN client running in the background and relaunches it if it crashes or restarts.
- Block connections without VPN (Lockdown): A strict fail-safe. If the VPN route drops, Android refuses to let apps fall back to your normal, unprotected cellular or Wi-Fi data.
When you pair these two, Android creates a walled garden. If the VPN tunnel stalls or fails silently, lockdown does exactly what you asked it to do: it kills all outgoing traffic. The phone looks fully connected across every status indicator, yet it accomplishes nothing.
To isolate the failure, trace the symptom against this diagnostic map:
- Nothing loads even after disabling the VPN: The underlying Wi-Fi or mobile service is down.
- Mobile data works, but one specific Wi-Fi fails: The problem is that local network's terms, portal, or firewall rules.
- Ordinary internet works fine, but all traffic stops the second the VPN turns on: The VPN route itself is broken.
- Most apps load normally, but a specific app or work profile fails: You are facing a split-tunneling or enterprise routing rule.
- Everything works initially, but dies after sleep or walking from Wi-Fi to cellular: The tunnel’s background recovery mechanism is failing.
Each pattern points to a different layer of the stack. Treat them accordingly.
Use Lockdown as a Diagnostic Switch, Not a Workaround
The highest-value diagnostic move takes ten seconds: isolate the underlying connection before touching a single advanced VPN setting.
Go to Settings > Network & internet > VPN, tap the gear icon next to your client, and temporarily toggle off Block connections without VPN (or disconnect the VPN briefly). Then open a browser and load a standard webpage.
If the page still does not load: Stop troubleshooting your VPN entirely. Your phone does not have functional internet access. Toggle between Wi-Fi and mobile data to see if one carrier path is alive, reset your connection, or look into local outage issues. Google's core connectivity guidance starts here for a reason: a VPN cannot encrypt and route data over a path that does not exist.
If the webpage immediately loads: Your base network is healthy. You have definitively proven that the failure sits within the VPN tunnel or its routing rules.
Now, do not leave lockdown turned off as a lazy fix. Disabling lockdown permanently strips away your leak protection, meaning applications will quietly transmit unencrypted data over public networks whenever the tunnel hiccups. Treat this switch as an investigative tool, not the solution.
(Note: If your device or work profile is managed by an employer, these toggles may be greyed out. Android Enterprise allows IT administrators to strictly enforce Always-On and lockdown modes. If that applies to you, do not attempt to bypass it; hand the diagnostic result directly to your IT helpdesk.)
If It Fails on One Wi-Fi but Works on Mobile Data, Fix the Network
If your connection hums along on 5G but stalls the moment you connect to a hotel, coffee shop, or airport network, the problem is almost certainly local.
The most common culprit is a captive portal. Public networks routinely require you to accept terms, enter a room number, or submit an email address before they grant external internet access.
When Block connections without VPN is active, Android blocks the very browser traffic required to load that sign-in splash screen. The network waits for you to sign in; your phone refuses to talk to the network until the VPN connects; the VPN cannot connect without external internet. You are stuck in a dead-end loop.
The fix is sequential:
- Temporarily turn off Block connections without VPN (or disconnect the VPN).
- Open your browser, navigate to any basic webpage to trigger the splash screen, and complete the authorization.
- Confirm normal web pages load.
- Re-enable your VPN and turn lockdown back on.
If you have cleared the sign-in screen—or if the network does not use one—and the VPN still chokes while ordinary web traffic works, that specific Wi-Fi is actively dropping, filtering, or throttling common VPN protocols. In that case, switching internal protocol settings or restrictive-network modes inside your VPN app is relevant. But remember the baseline rule: no VPN can forge a tunnel across a guest network that has not granted your phone basic network clearance.
If Only Certain Apps Are Offline, Stop Blaming the Tunnel
When one app refuses to connect while Chrome browses without issue, the tunnel itself is healthy. You are dealing with application-level boundaries.
Android allows VPNs to implement split-tunneling through "allowed" and "disallowed" application lists. Work profiles enforce similar boundaries across personal and enterprise workspaces.
Under normal circumstances, an app excluded from the VPN simply uses your normal Wi-Fi or cellular connection directly. However, when paired with Block connections without VPN, Android's security stance hardens: an app excluded from the VPN may be blocked from accessing the internet altogether because bypassing the tunnel is strictly forbidden.
If you find yourself in this situation:
- Open your VPN client's settings and verify its Split Tunneling or Bypass list. If a broken app was excluded, bring it back into the tunnel.
- Check if the problem is confined to a Managed Work Profile, where corporate security policies isolate data paths regardless of personal settings.
- If you manually configured an alternative Private DNS provider in Android's network settings and the outage started immediately afterward, verify that hostname. Otherwise, leave Android's default Private DNS alone rather than treating it as a generic toggle.
If It Breaks After Wi-Fi → 5G or Screen-Off, the Missing Feature Is Recovery
If your baseline network is fine, captive portals are cleared, all apps are routed identically, and the connection works initially—only to die silently when you put the phone in your pocket or step out of the house—you have isolated the real issue: handoff recovery.
Android's Always-On architecture is responsible for keeping the VPN app running. But maintaining a viable data route across migrating network interfaces is the VPN software’s job.
When your phone switches from home Wi-Fi to a 5G tower, your local IP address changes, routes tear down, and packets drop. Under Android’s lockdown mode, an interrupted tunnel causes an immediate, hard blackout. A VPN that handles handoffs poorly will leave the Android key icon showing while its internal routing remains dead, requiring you to open the app and manually toggle the switch several times a day.
You can verify this failure pattern with a simple test:
- Connect via Wi-Fi with lockdown enabled.
- Load a stream, live feed, or webpage to verify data is moving.
- Turn off Wi-Fi to force a handoff to mobile data.
- Do not touch the VPN app. Wait ten seconds and try loading a new page.
If data stalls indefinitely until you intervene manually, stop judging VPNs by server counts or static desktop speed tests. On a mobile operating system, tunnel recovery is the foundational metric of quality.
Many traditional clients stumble during mobile handoffs because their underlying tunnels do not adapt cleanly to shifting IP addresses and restrictive network states. OnlydogVPN↗ is built around an HTTP/3-based transport designed explicitly for unstable and transitioning paths, paired with automatic route selection. Instead of leaving you to manually cycle through server lists when a handoff degrades, its architecture detects network state changes and re-establishes a valid route transparently.
If your Always-On setup works on your desk but falls apart the moment Android switches networks, do not weaken your security posture by disabling Android's lockdown mode. Keep the lockdown protection intact and replace the weak link underneath it: the recovery mechanism of the VPN itself.
OnlydogVPN will not bypass a captive portal you have not signed into, and it cannot revive a dead cellular carrier. Its relevant role here is the narrower one: recovering the tunnel when Android moves between viable networks under strict Always-On protection.
The Takeaway
The key in your status bar confirms that Android is running a process. It does not guarantee that your traffic is reaching the world.
The next time your phone goes silent, resist the urge to randomly flip switches. Strip the problem to its boundary: does the failure follow the underlying network, the VPN route, a specific app, or the transition between towers?
Find the boundary, and the fix reveals itself immediately.
Frequently Asked Questions
Why does Android show my VPN as connected when there is no internet?
Always-On VPN can keep the VPN service process running even when the tunnel no longer has a usable data route. With lockdown enabled, Android then blocks ordinary fallback traffic, so the status icon can remain while apps are effectively offline.
Should I permanently turn off “Block connections without VPN” to fix this?
No. The article uses it only as a short diagnostic switch to prove whether the underlying network works. Leaving it off permanently removes the fail-closed protection that prevents apps from silently using the direct connection when the VPN breaks.
Why does the VPN work on mobile data but fail on one Wi-Fi network?
That pattern points to the local Wi-Fi: a captive portal may not be completed, or the network may be filtering or throttling the VPN transport. Finish normal network access first, then reconnect the VPN.
Why does an Android Always-On VPN die after switching from Wi-Fi to 5G?
The local IP and route change during the handoff. Android keeps the VPN app alive, but the VPN client still has to rebuild a viable tunnel. If it cannot recover cleanly, lockdown turns the handoff into a hard blackout until the route is restored.