In short: If LiMP VPN on Android shows "Connected" but the internet still doesn't work, the problem is almost always one of four things: Private DNS intercepting queries before the tunnel, a VPN profile conflict, an outdated app, or a protocol that doesn't pass through your current network. Check in that order — most cases are resolved in five minutes. If you haven't set up VPN yet, start with the Android VPN setup guide.
Understanding Where It Broke: Three Diagnostic Levels
Before changing any settings, identify which layer the problem is at: device, local network, or VPN server. The right diagnosis saves 15–20 minutes and gets you straight to the relevant section below. Statistically, more than two thirds of "VPN not working on Android" cases originate at the device level.
Level 1 — Device (App and Android OS)
Start here. Most "VPN connected but no internet" cases on Android are resolved without touching the router or server.
- Force-close the app and reopen it: long-press the LiMP VPN icon → Stop, or swipe it from recent apps, then open again.
- Check the app version: Google Play → LiMP VPN → if "Update" is available, tap it. An outdated client is a common cause of connection failures, especially after OS updates.
- Check permissions: Settings → Apps → LiMP VPN → Permissions. The app needs permission to establish VPN connections. Without it, Android won't activate the TUN adapter.
- Battery and background mode: Settings → Apps → LiMP VPN → Battery → "Unrestricted". Aggressive battery optimisation can kill the VPN process in the background.
Level 2 — Local Network (Wi-Fi and Mobile Data)
If the device is fine, check the network. Conflicts at the Wi-Fi router or mobile carrier level produce the same symptoms as app problems.
- Switch between Wi-Fi and mobile data. If VPN works on one but not the other, the cause is clear.
- Check Private DNS: Settings → Network & Internet → More → Private DNS. If it shows a hostname or is set to "Automatic", switch to "Off" and reconnect to VPN.
- Reboot the router if the problem only occurs on Wi-Fi.
Level 3 — VPN Server
If device and network are fine, the problem may be on the server side — rare but possible during maintenance or high load.
- Switch servers in the LiMP VPN app: tap the current location and pick a different one.
- If switching servers helps, the previous node was temporarily overloaded — it will recover on its own.
Quick Checklist: First Five Minutes
Before diving into individual causes, run through this checklist in order. It resolves about 70% of "VPN not working on Android phone" cases.
- Test internet without VPN: disconnect VPN and try opening any website. No connection means the problem is your basic internet, not VPN. If you haven't configured VPN yet, read the VPN setup guide for Android first.
- Reboot your phone: a simple restart clears temporary faults in the Android network stack and resolves up to 20% of issues.
- Disable Private DNS: Settings → Network & Internet → More → Private DNS → "Off". Reconnect to LiMP VPN.
- Check for VPN profile conflicts: Settings → Network & Internet → VPN. Ensure only one VPN profile is active; remove or disconnect the rest.
- Change the VPN protocol: in LiMP VPN settings try WireGuard, then IKEv2, then OpenVPN.
- Update app and OS: Google Play → LiMP VPN → Update, plus Settings → About phone → System update.
- Switch servers: select a different VPN location in the LiMP VPN app.
Eight Reasons Why VPN Is Not Working on Android and How to Fix Each
If the checklist didn't resolve it, here is a detailed breakdown of each cause — what it is, how to identify it, and the exact path to fix it.
1. No Internet Without VPN
The most commonly overlooked cause: VPN doesn't create an internet connection — it encrypts and routes one that already exists. If websites don't load without VPN, the VPN itself isn't the problem.
Check in 30 seconds: disconnect VPN and open a website. Nothing loads? Restart your phone, toggle airplane mode on and off, check your carrier balance, or reboot the router. Only once basic internet works without VPN does it make sense to investigate the VPN itself.
2. VPN Profile Conflict: Android Only Supports One Active Profile
Android allows multiple VPN profiles but only one can be active at a time. If your settings contain profiles from other apps — a corporate VPN, a previous privacy app — one of them may be holding the TUN interface, preventing LiMP VPN from establishing its own tunnel. The key indicator in the status bar shows a VPN is active, but it belongs to a different profile.
To check: Settings → Network & Internet → VPN (on some ROMs: Advanced settings → VPN, or search "VPN" in Settings). Only LiMP VPN should be listed as connected. Remove any other profiles: tap the gear icon next to each → "Forget VPN".
Also check Always-On: Settings → Network & Internet → VPN → each profile → Always-On VPN. Enable it only for LiMP VPN; disable for all others.
3. Private DNS Interferes with Routing (Android 9 and Later)
Private DNS is a built-in Android 9+ feature that sends DNS queries over an encrypted TLS connection before the VPN tunnel can process them. The result: VPN is "Connected" but DNS resolution bypasses the tunnel — some queries leak, others fail entirely. This is the classic "connected but nothing opens" symptom that's confusing precisely because the VPN indicator is green.
You can verify a DNS leak after fixing it with the tools described in the article how to check for DNS leaks. If the result shows your ISP's servers instead of VPN provider servers, Private DNS is intercepting queries.
Fix: Settings → Network & Internet → More (or "Advanced network settings") → Private DNS → select "Off". Restart LiMP VPN. On Xiaomi MIUI: Settings → Connection & sharing → Private DNS.
4. Outdated App or Android Version
Each major Android upgrade — 12→13, 13→14 — changes how the TUN interface, app permissions, and background process management work. A VPN client that hasn't been updated for the new OS may lose permissions or fail to interact with the system VPN API correctly.
Two mandatory steps:
- Update LiMP VPN: Google Play → search "LiMP VPN" → Update (or My apps & games → Updates).
- Update Android: Settings → About phone → System update.
If the issue appeared right after an Android update and updating the app didn't help — uninstall LiMP VPN completely (clear data) and reinstall from Google Play. A fresh install resets all permissions and recreates the system profile. Note your account credentials before uninstalling.
5. Antivirus or Firewall Blocking the TUN Adapter
The TUN adapter is a virtual network interface through which LiMP VPN routes all your device's traffic. Some mobile antivirus apps (Kaspersky, Avast, Bitdefender Mobile, Dr.Web) and built-in security mechanisms in custom Android ROMs treat TUN adapter creation as suspicious network modification and block it. This is particularly common in MIUI (Xiaomi), HyperOS, OneUI (Samsung), and ColorOS (OPPO/Realme).
Symptoms: the app shows "Connected" but no traffic flows; your antivirus shows a notification about a blocked network request; the app hangs on the connecting screen without showing an error. For a detailed look at how VPN and security software interact, see VPN and antivirus: how they work together.
Fixes by platform:
- Third-party antivirus: open the antivirus → Exclusions or Trusted Apps → add LiMP VPN. Also disable "DNS protection" or "DNS filtering" if present.
- MIUI/HyperOS (Xiaomi): Security → App management → LiMP VPN → allow "Modify network settings". Also: Security → Autostart → enable for LiMP VPN.
- OneUI (Samsung): Settings → Biometrics and security → Other security settings → Device admin apps — ensure no other VPN app holds admin privileges.
6. System Clock Out of Sync (Critical for IKEv2 and WireGuard)
IKEv2/IPsec and WireGuard verify the device clock during the authentication handshake. A discrepancy of more than 5 minutes between the device and the VPN server causes an automatic connection refusal — the system treats the certificate as expired or not yet valid. Externally this looks like "authentication failed" or an indefinite timeout with no explanation.
Most likely scenario: the device was without a SIM card, in airplane mode, or offline for a long time — automatic NTP synchronisation wasn't performed.
Fix: Settings → General → Date & time (or System → Date & time) → ensure "Automatic date & time" is enabled. If it's already on, toggle it off and back on to force immediate NTP sync. Reconnect to VPN after synchronisation.
7. MTU Fragmentation and Packet Loss
MTU (Maximum Transmission Unit) is the maximum packet size for a single transmission. Standard Ethernet MTU is 1500 bytes. A VPN tunnel adds encryption headers to every packet, reducing the usable MTU inside the tunnel to roughly 1380–1420 bytes. If the carrier or router is configured with an even lower MTU, large packets are dropped in transit.
The signature MTU symptom: VPN is connected, small text-only pages load fine, but pages with many images, video, or heavy CSS stall mid-load. WireGuard defaults to MTU 1280 in its config specifically to minimise fragmentation on mobile networks.
LiMP VPN sets MTU automatically. If MTU fragmentation symptoms persist — switch from WireGuard to IKEv2: different encapsulation parameters sometimes work better with restrictive carriers.
8. Protocol Incompatibility with the Current Network
Different VPN protocols have fundamentally different ability to pass through carrier networks, corporate firewalls, and home routers. WireGuard is UDP-only — some carriers throttle or block UDP on non-standard ports. OpenVPN TCP on port 443 passes nearly everywhere because it looks like HTTPS traffic. IKEv2 performs well on mobile networks but may be blocked by a strict corporate proxy.
The tell-tale sign: VPN doesn't work on a specific network (office Wi-Fi, a café, a particular carrier) but works fine at home or on a different SIM. Step-by-step instructions for switching are in the article how to change the VPN protocol in LiMP VPN.
Recommended sequence when a specific network is blocking VPN: WireGuard → IKEv2 → OpenVPN TCP. After each protocol change, disconnect and reconnect VPN before concluding it doesn't work.
Symptom Table: What's Happening → Likely Cause → Fix
Use this table as a quick navigator: find your symptom on the left and jump to the relevant section.
| Symptom | Likely Cause | Fix |
|---|---|---|
| VPN connected but no internet | Private DNS / profile conflict | Disable Private DNS, check for profile conflicts |
| VPN won't connect (timeout) | Wrong protocol or port | Switch protocol (WireGuard → IKEv2 → OpenVPN) |
| App hangs on "Connecting…" screen | Outdated app or OS version | Update Android and LiMP VPN |
| VPN works on Wi-Fi but not mobile data | Carrier restricts UDP/protocol | Switch to IKEv2 or OpenVPN TCP |
| VPN stopped working after Android update | TUN permissions reset | Reinstall app, re-enable Always-On VPN |
| Antivirus warns about VPN | False positive on TUN interface | Add LiMP VPN to antivirus exclusions |
| "Authentication failed" or endless timeout | System clock out of sync | Enable "Automatic date & time" in settings |
| Pages load partially, video stalls | MTU packet fragmentation | Switch WireGuard → IKEv2, or try a different server |
LiMP VPN Settings on Android to Check
Once basic diagnostics are done, check the key parameters inside the app — sometimes the problem is in the client configuration rather than Android itself.
- Protocol: WireGuard is the default — fast and battery-efficient on mobile. IKEv2 handles network switches (Wi-Fi ↔ mobile data) better. OpenVPN TCP is the most permissive, passing through the vast majority of restrictive networks.
- Kill Switch: when enabled, Android blocks all traffic the moment the VPN drops — correct for continuous data protection. Make sure Battery Optimisation isn't stopping VPN in the background, or Kill Switch will unexpectedly cut your internet.
- Split tunnelling: routes only selected apps through VPN, or excludes specific apps from the tunnel. See the full guide at VPN split tunnelling. If your browser is on the "no VPN" exclusion list, that's why it appears unprotected.
- Always-On VPN via Android system settings: automatically reconnects VPN when the network changes. Settings → Network & Internet → VPN → LiMP VPN → Always-On VPN. Also enable "Block connections without VPN" for the strongest protection.
All current LiMP VPN features and advanced settings are documented on the LiMP VPN features page.
When the Problem Is Your Network and Router
If LiMP VPN works on mobile data but not through your home Wi-Fi (or a specific router), the issue is in the network hardware, not the app itself.
Typical network causes: the router blocks the UDP ports WireGuard needs, WAN MTU is set below 1480 bytes, or hairpin NAT mishandles VPN packets. Step-by-step fixes for each are in a dedicated guide: VPN not working over Wi-Fi: what to do.
Quick test: switch from Wi-Fi to mobile data (turn off Wi-Fi). If VPN immediately starts working — the problem is in your router settings or ISP equipment, not the phone.
VPN Works on Other Devices but Not Android: What to Check
If the same LiMP VPN account works normally on a PC or iPhone but fails on Android, the issue is Android-specific platform behaviour. Here's what to check first.
- Battery optimisation: Android can forcibly stop the VPN process in the background when the screen is off — especially with aggressive power saving profiles. Fix: Settings → Apps → LiMP VPN → Battery → "Unrestricted" (or "No restrictions", wording varies by ROM). On MIUI: Security → Background apps management → LiMP VPN → "No restrictions".
- Doze Mode: Android's deep sleep mode blocks all network activity during extended idle periods. Always-On VPN partially bypasses Doze (Android 7+), but only when Battery Optimisation is also disabled. Both settings must be configured together.
- Always-On VPN as a built-in Kill Switch: forces all traffic through VPN and blocks connections when VPN drops. Enable via: Settings → Network → VPN → [LiMP VPN] → Always-On VPN. If the option is greyed out, either the app doesn't support Always-On via the system API, or another profile already has it active.
- MIUI "Second Space" and Work Profile: if LiMP VPN is installed in the main profile, the TUN adapter is unavailable in Second Space or Work Profile. Install LiMP VPN separately in each profile where you want a private connection.
VPN problems on other platforms are covered in separate articles: VPN not working on iPhone and the Windows PC troubleshooting guide.
Frequently Asked Questions
Why is VPN connected but the internet not working on Android?
Most often it's Private DNS (Settings → Network & Internet → More → Private DNS → Off) or a conflict between two simultaneously active VPN profiles. Check both in order — one of them is almost always the culprit.
What to do if VPN works on Wi-Fi but not on mobile data?
Your carrier may be restricting certain protocols or UDP ports. Try switching the protocol in LiMP VPN settings (WireGuard → IKEv2 or vice versa). If that doesn't help, try OpenVPN TCP, which passes through most carrier restrictions. More detail in the article on VPN and mobile data.
Why does no VPN work on my Android phone at all?
If every VPN app fails to connect, reset Android network settings (Settings → General → Reset → Reset network settings) and check whether an antivirus or the OS VPN manager is blocking the TUN interface. Also ensure apps are allowed to run in the background.
What is Always-On VPN on Android and how do I enable it?
Always-On VPN forces all traffic through VPN and blocks the network when the VPN drops — it's Android's built-in Kill Switch equivalent. Enable it at: Settings → Network → VPN → [app name] → Always-On VPN. If the option is unavailable, the app doesn't support Always-On through the Android system API.
