A VPN that keeps disconnecting is rarely caused by a single setting. The interruption may come from an unstable local network, a protocol that does not suit the current carrier path, an operating system putting the client to sleep, or a subscription configuration that no longer works correctly. A client showing “Connected” also does not prove that the tunnel will remain usable when the device changes networks, locks its screen, or resumes from standby.
The most efficient troubleshooting method is to identify when the drop occurs, separate local problems from route problems, and change one variable at a time. Do not immediately delete every profile or switch between several clients. Record the conditions first: device, network type, selected node, protocol, whether the screen was locked, and whether other applications were downloading data. That short record helps you avoid repeating the same unsuccessful changes.
Identify the Disconnection Pattern First
Start by observing the timing and symptoms. A connection that drops only when moving from Wi-Fi to mobile data points to network transition handling, while a connection that fails after the screen is locked often indicates battery optimization or background restrictions. If every node disconnects on the same network, the local connection or client environment deserves attention. If only one route fails while other routes remain connected, the selected node, protocol, or upstream path is more likely to be involved.
There are also different meanings behind the word “disconnect.” Some clients show a clear transition from Connected to Disconnected. Others remain connected but stop forwarding traffic, leaving websites loading indefinitely or applications reporting a timeout. A third situation is a repeated reconnect loop: the client briefly establishes a tunnel, loses it, and tries again. These symptoms require different checks.
90+
Countries covered
200+
Available routes
Unlimited
Concurrent devices
7 days
Refund window
Before changing anything, answer these questions:
- ✅ Does the drop happen on one network, or on both Wi-Fi and mobile data?
- ✅ Does it affect one node, one protocol, or every imported configuration?
- ✅ Does the problem begin after the device sleeps, locks, or switches networks?
- ✅ Can ordinary websites open when the VPN is disconnected?
- ❌ Do not judge stability from the client status alone; test an actual website or application.
If the local internet itself is already unstable, changing VPN nodes will not solve the underlying problem. If the local connection is steady but the tunnel repeatedly fails, continue with protocol, route, and client checks.
Check the Local Network Before Changing Routes
A VPN adds another connection layer on top of your existing internet access. The client must first reach its entry server, negotiate authentication, establish encryption, and then maintain traffic through the tunnel. A weak Wi-Fi signal, captive portal, overloaded router, unstable mobile handoff, or restrictive public network can interrupt that process before the remote route has a chance to work.
Test the same device without the VPN connected. Open several ordinary websites, reconnect to the Wi-Fi network, and check whether the device can continue browsing after remaining idle. If the unprotected connection also drops, restart the local router or change to a more stable network before investigating the VPN. On public Wi-Fi, complete any browser-based sign-in or access confirmation first; a VPN client may not be able to complete that portal exchange automatically.
Network transitions deserve special attention. A phone may move between Wi-Fi and mobile data without clearly notifying every application. A laptop may wake from sleep with an old gateway, DNS server, or wireless lease. In these situations, disconnect the VPN manually, confirm that the new network can browse normally, and reconnect. Enabling an automatic connection feature can help later, but it should not be used to hide an unresolved network transition problem.
DNS symptoms can look like a disconnection. The tunnel may still be active while domain names fail to resolve, resulting in blank pages or repeated timeouts. Compare a domain-based website with a service that you already know is reachable by another method. Avoid repeatedly changing DNS settings without recording the original configuration, because custom DNS, system DNS, and client DNS can interact differently on Windows, macOS, Android, iOS, and Linux.
Choose a Suitable Protocol and Route
Protocols are not interchangeable labels for speed. They define how the client authenticates, encrypts, transports, and maintains the connection. A protocol that performs well on a fixed broadband connection may be less reliable on a mobile network or a restrictive public network. The correct choice depends on client support, transport behavior, network conditions, and the route provided by the service.
Shadowsocks is commonly used as a lightweight proxy protocol and may be available in many compatible clients. VMess and Trojan use different authentication and transport arrangements and must be imported into a client that supports the corresponding format. Hysteria2 is designed around a different transport approach and may behave differently when packet loss or traffic shaping is present. WireGuard is a VPN protocol with its own key and peer configuration model; it is not the same thing as a generic subscription format. Do not paste a WireGuard configuration into a field intended for a Shadowsocks, VMess, or Trojan subscription.
If a route disconnects repeatedly, select another route using the same protocol first. This helps determine whether the problem belongs to the node rather than the protocol. If several routes using one protocol fail but another supported protocol remains stable, compare protocols on the same network. Use one change per test and give the connection enough time to encounter the original failure condition, such as screen locking or a network switch.
| Observed symptom | Likely area | Useful check | Avoid doing first |
|---|---|---|---|
| Only one route disconnects | Node load, route path, or server configuration | Try another route with the same protocol and compare behavior | Deleting the entire subscription immediately |
| Every route fails on one Wi-Fi network | Router, captive portal, DNS, or network restriction | Test another network and browse without the VPN first | Changing several client settings at once |
| Connection drops after sleep | Background policy, wake-up handling, or stale network state | Review battery and background permissions, then reconnect after wake-up | Assuming the route is permanently unavailable |
| Client says connected but pages time out | DNS, system proxy, routing rules, or a stale tunnel | Reconnect, check DNS behavior, and inspect split-tunneling rules | Running two proxy clients simultaneously |
| Repeated reconnect loop | Protocol compatibility, credentials, or an invalid configuration | Update the subscription and test a supported alternative configuration | Mixing profiles from unrelated services |
Route labels also need careful interpretation. A country name does not describe the complete path, and a city name does not guarantee identical upstream connectivity. Services may distinguish ordinary routes, BGP transit, CN2, or IEPL-style dedicated paths, but the label should be treated as a starting point rather than proof of stability on your specific network. The most useful comparison is repeatable behavior under the same device and access network.
Fix Background Restrictions and Client Conflicts
Mobile and desktop operating systems may restrict applications that remain active in the background. Battery-saving modes, app sleeping, background data limits, automatic process cleanup, and permission changes after a system update can all interrupt a VPN client. The exact menu names vary by operating system and device manufacturer, but the required checks are similar: allow the client to run in the background, permit network access, and exclude it from aggressive battery optimization when persistent connectivity is necessary.
On Android, inspect battery usage, background activity, unrestricted data access, and any manufacturer-specific auto-start or memory-cleaning controls. On iOS, check whether the VPN profile is still present and trusted, whether Low Power Mode changes the behavior you observe, and whether the client has permission to establish the VPN configuration. On Windows and macOS, check firewall prompts, network-extension permissions, sleep behavior, and whether security software is blocking the client’s tunnel or helper process. On Linux, verify that the desktop client, NetworkManager profile, or command-line service is still running after suspend and network changes.
Do not run two full proxy or VPN clients at the same time unless you understand how their routing layers interact. Clash Verge, sing-box, and Shadowrocket each manage their own profiles and rules in different ways. An official QaVPN client may also create a system-level tunnel or proxy setting. Running multiple clients can produce port conflicts, competing DNS settings, circular routing, or a status that appears connected while traffic is sent through another process.
Choose one client for the test. Turn off the others, disable their system proxy or VPN profile, and restart the selected client. If you use a third-party client, confirm that its imported format matches the subscription. A link intended for a sing-box profile is not automatically a complete Clash Verge configuration, and a Shadowrocket-compatible import does not mean every protocol option will behave identically on desktop systems.
Perform a Clean Reconnection Test
- Disconnect the VPN and close other proxy clients, browser extensions, and traffic-routing tools.
- Confirm that ordinary internet access works on the current Wi-Fi or mobile network.
- Open one client only and verify that its account session is valid.
- Update the subscription or configuration from the service panel instead of reusing an old copied entry.
- Select one supported route and protocol, then connect.
- Open a website and a normal application to verify actual traffic, not just the status indicator.
- Lock the device, wake it again, and check whether the tunnel recovers without producing a reconnect loop.
- Write down the result before testing a different route or protocol.
If the clean test succeeds, re-enable settings one at a time. Start with split tunneling, then automatic startup, then custom DNS or rule sets. When the disconnection returns, the last change is a strong candidate. If the clean test fails, the problem is less likely to be caused by a complicated local rule set and more likely to involve the network, route, protocol, account, or client compatibility.
Refresh Subscriptions and Verify Routing
A subscription link is a way to retrieve configuration data; it is not the connection itself. The returned configuration may include server addresses, protocol details, transport parameters, credentials, and routing metadata. If a provider replaces a route, changes a certificate, or removes an entry, an outdated local profile may continue trying to use information that is no longer valid.
Update the subscription from inside the client and inspect whether the server list changes. If the update fails, check the link for accidental spaces, line breaks, expired account access, or use in an incompatible client. Treat the link as sensitive account information. Do not post it in a public troubleshooting forum or submit it to an unknown online converter. If you believe it has been exposed, replace or reset it through the service panel where that option is available.
After connecting, verify the system proxy and split-tunneling rules. A rule may intentionally send some applications directly while routing others through the tunnel. That behavior can be mistaken for random disconnection when only selected domains or applications fail. Test with a simple browser request, then test the application that originally showed the problem. If only one application fails, inspect its own proxy settings, certificate handling, DNS behavior, and connection persistence.
For a more reliable comparison, use the same client, route, protocol, and network while testing. Check the behavior before and after the device sleeps, after reconnecting Wi-Fi, and during a normal task such as browsing or file transfer. Avoid treating one successful page load as proof of long-term stability, but also avoid changing five variables after one failed request.
- ✅ Import the subscription into a client that supports its format.
- ✅ Update old configurations before concluding that every route is unavailable.
- ✅ Verify system proxy, DNS, and split-tunneling behavior separately.
- ✅ Keep a known-working profile as a comparison point.
- ❌ Never share a subscription link publicly or paste it into an untrusted diagnostic service.
Know When to Contact Support
Contact support after collecting useful diagnostic details rather than sending only “VPN keeps disconnecting.” Include the operating system, client name and version if available, network type, approximate time pattern, selected route, protocol, whether the screen was locked, and whether another route worked. Do not include passwords, private keys, or the complete subscription link. A redacted configuration name and a screenshot with account-sensitive fields hidden are safer.
Explain whether ordinary internet access works without the VPN, whether the failure affects all clients, and whether the issue began after a system update, router change, subscription update, or network switch. This information helps separate an account or configuration problem from a local firewall, DNS, or background-policy issue. If a route works on mobile data but not on home broadband, say so explicitly; the difference is more informative than a general statement that the service is unstable.
QaVPN supports Windows, macOS, iOS, Android, and Linux, and compatible users may also work with clients such as Clash Verge, sing-box, or Shadowrocket when the imported format and protocol support match. If you need a fresh client or account-side configuration check, use the download page or contact support. For plan questions, the service offers monthly subscriptions of ¥9.9/month with 60GB, ¥18/month with 250GB, and ¥28/month with 500GB; traffic is reset monthly from the activation date. There are also traffic packages that do not expire, and the service provides a 7-day no-questions-asked refund policy.
FAQ
Why does my VPN disconnect whenever the phone screen is locked?
Battery optimization, background restrictions, or manufacturer process cleanup may be stopping the client. Allow background activity and network access, review battery settings, then reconnect after the device wakes. If the issue continues, compare another supported client or route on the same phone.
Should I change the protocol when one route keeps dropping?
Test another route with the same protocol first. If several routes using that protocol fail while another supported protocol remains stable on the same network, a protocol comparison is reasonable. Change only one variable at a time so the result remains meaningful.
Can two VPN or proxy apps be enabled together?
It is usually better to use one active routing client during troubleshooting. Multiple clients can compete for system proxy settings, DNS, ports, or tunnel ownership. Disable the others and remove their active system profiles before running a clean reconnection test.
Why does the client say connected while websites do not open?
The tunnel may be active while DNS, split-tunneling rules, system proxy settings, or the application itself prevents traffic from reaching the destination. Reconnect, test a normal website, inspect routing rules, and compare with another route before reinstalling the client.