Guides / VPN connected but no internet or can't reach internal sites
Last reviewed 5 Oct 2026
VPN connected but no internet or can't reach internal sites
VPN says connected but nothing loads, or internal sites fail? DNS, split tunnelling, overlapping home subnets and MTU, explained with the tests to run.
The VPN client shows a green tick. Nothing loads. Or the internet works but the intranet, the file server and the finance system do not. "Connected" only means the tunnel came up. Whether traffic can get through it, and whether names can be found, are separate questions.
First: what kind of VPN is it?
- Full tunnel sends everything, including web browsing, through the office. If the office's internet path or proxy is broken, nothing loads.
- Split tunnel sends only company networks through the VPN. Internet works locally; internal sites depend on routes and DNS being right.
Ask IT which one you have, or look at the routes (below). If the VPN is a cloud service, such as Cloudflare WARP / Zero Trust or an Azure VPN gateway, check the Cloudflare or Azure page. For an appliance in your own office, no public status page will help.
User-level checks
- Disconnect and test the internet. If the internet does not work without the VPN, fix that first. Hotel and café Wi-Fi often needs you to accept a sign-in page before the VPN can work.
- Reconnect once. Then restart the VPN client completely. Clients that have been asleep overnight often hold stale routes.
- Try by IP address. If you know an internal server's IP, try it. If the IP works and the name does not, it is DNS.
- Check your home network range. Many home routers use 192.168.0.x or 192.168.1.x. If the office uses the same range, your PC cannot tell which is which and internal sites fail. Testing from a phone hotspot (which uses a different range) proves it.
- Try another network. Some networks block VPN protocols. A phone hotspot is the quickest comparison.
The tests IT will ask for
On Windows, in a terminal:
ipconfig /all— shows the VPN adapter, its IP address and the DNS servers it was given.route print— shows which networks go through the VPN.nslookup intranet.yourcompany.local— tests whether the internal name resolves, and which DNS server answered.Test-NetConnection server.yourcompany.local -Port 443in PowerShell — tests whether a specific service is reachable through the tunnel.ping -f -l 1400 server.yourcompany.local— if large packets fail while small ones work, it is MTU (see below).
On a Mac, scutil --dns shows the DNS configuration and netstat -rn shows routes.
Admin-level causes
- DNS. The VPN must hand out internal DNS servers, or a rule that sends the company's domain to them. If the client keeps using the home router for DNS, internal names will never resolve. On Windows, the Name Resolution Policy Table is one way to direct specific domains to internal DNS.
- Overlapping address ranges. If the office LAN uses a common home range, renumbering the office or the VPN pool is the real fix. Route tweaks on each laptop are a sticking plaster.
- MTU. VPN encapsulation adds overhead. If the path cannot carry full-size packets and fragmentation is blocked, small requests work and large ones hang: login pages load, file copies stall. Clamping TCP MSS on the VPN gateway is the standard fix.
- Full-tunnel bottlenecks. Sending Microsoft 365, Teams and Zoom traffic back through head office slows everything. Microsoft recommends sending its "Optimize" category of traffic directly, outside the VPN; see Microsoft's guidance on Microsoft 365 URLs and IP address ranges.
- Firewall rules. The VPN user group needs rules to reach the internal subnets and ports. A new server that nobody added to the VPN rules is a classic.
- Certificates and posture. Expired client certificates or failed device posture checks can let the tunnel come up with no access.
When to escalate
Escalate to the network team when several users on different home networks get the same failure, or when the tests show the VPN handing out wrong DNS or routes. Escalate to a cloud VPN vendor only when their status page names your region or service. If only one user fails and they are on a 192.168.1.x home network, the fix is probably the address overlap, not the vendor.
Related status pages
Related guides
- Why a site works for everyone else but not me
- How to tell if a service is down or it's just you
- Teams video calls freezing: outage or network?
FAQ
- Why does my VPN say connected but I have no internet?
- With a full-tunnel VPN, all traffic goes through the office, so an office internet or proxy problem stops everything. DNS servers that the VPN assigns but cannot reach, and captive Wi-Fi pages, cause the same symptom.
- Why can't I reach internal sites over VPN?
- Usually DNS: the PC is not using the company's internal DNS servers for internal names. Overlapping home and office IP ranges and missing firewall rules are the next most common causes.
- What is split tunnelling?
- Split tunnelling sends only company traffic through the VPN and lets everything else, such as web browsing and often Microsoft 365, go directly to the internet. It reduces load on the office connection.
- Will a different VPN fix a vendor outage?
- No. A VPN changes the path between you and a service. It cannot fix a service that is down for everyone.