School, work, and public Wi-Fi
Many school, office, hotel, airport, and other public networks interfere with VPN traffic on purpose. If WorkingVPN works on your home internet but fails on one specific network, the network is almost certainly the cause rather than the app.
How these networks block VPNs
Administrators have a few tools available:
- Port blocking. The firewall allows only standard web ports, 80 and 443, and drops everything else. VPNs that use their own ports never get out.
- Deep packet inspection. The firewall looks at the shape of the traffic rather than just its destination. Many VPN handshakes have a recognisable pattern that can be spotted and dropped even on port 443.
- DNS filtering. The network forces you onto its own DNS server, which refuses to resolve VPN-related hostnames.
- Captive portals. You have to sign in on a splash page before you can reach anything at all, the VPN server included.
Step 1: Finish the captive portal login first
This one catches almost everyone on hotel and airport Wi-Fi.
- Disconnect WorkingVPN if it is trying to connect.
- Open an ordinary website.
http://neverssl.comis useful here, because being plain HTTP it reliably triggers the portal instead of failing with a certificate error. - Complete whatever sign-in or “I agree” flow the network shows.
- Only once you can reach the open internet, connect WorkingVPN.
Step 2: Try a different location
Some blocks target specific address ranges rather than VPNs in general. Switching to a location in another country often gets around them, because the new server’s address is not on the list.
You do not need to hunt for a working server by hand. When a connection fails, the app moves on to the next server for that location by itself before reporting an error.
Step 3: Use the browser extension if the app won’t connect
There is no protocol setting to change. WorkingVPN uses transports chosen to blend in with ordinary web traffic, and picks them for you per location, so there is nothing to switch by hand on a restrictive network.
What does differ is the client. The browser extension connects over port 443, the same port as normal HTTPS, which makes it harder to block by port alone. If the desktop or mobile app cannot get out of a particular network but the extension can, use the extension while you’re on it.
Bear in mind the extension only protects traffic from that browser. Anything else on the machine still uses the network directly.
Step 4: Tether from a phone
If the network really is locked down, the simplest way through is to tether your laptop to your phone’s mobile data. Mobile carriers rarely filter VPN traffic. It is a way around the problem rather than a fix, but it will get you working.
What you can and can’t do here
- On a school or employer network you do not own, you are limited to what the administrator permits. Determined blocks are hard to get past, and your traffic may be logged either way.
- On a network you do own, such as home Wi-Fi or your own hotspot, you can change router settings, though there is rarely a need since these networks do not usually block VPNs.
- Using a VPN to get around your employer’s or school’s policy may breach their terms of use. Read the acceptable use policy before you do.
Related
- Managed devices and corporate proxies, if the problem follows the device rather than the network.
- Using WorkingVPN in a country that restricts VPNs, for country-level blocks rather than network-level ones.