VPN not working on iPhone: what to check
If a VPN does not work on an iPhone, in 9 cases out of 10 the reason is not the server itself, but how iOS handles VPN profiles. iOS tightly controls the tunnel: it may fail to come up because of an outdated profile, a conflict with another VPN, On-Demand mode, or after another system update.
The symptoms often look similar: the “VPN” switch turns on and immediately turns off, the VPN icon appears but websites do not open, or the connection drops every few minutes. These have different causes, and they are fixed in different ways.
Below is step-by-step diagnostics specifically for iOS: what to check in “Settings → VPN & Device Management”, which protocols work more reliably on iPhone, and how Russian operators’ DPI is involved. At the end, there is a quick availability check through Freedom Checker.
In short
- Check that only one VPN profile is active in “Settings → General → VPN & Device Management”.
- On iOS 17+, WireGuard is generally more stable than IKEv2: it drops less often when switching Wi-Fi ↔ LTE.
- If On-Demand with rules is enabled, temporarily disable it — it may block a manual connection.
- After an iOS update, delete and reinstall the VPN config: the old profile may have lost permissions.
- “Connected, but no websites” is almost always DNS or MTU. Switch DNS to the server-side setting, and set MTU to 1280–1380.
- If nothing helps, it is no longer the iPhone, but protocol blocking by the operator. Check through another channel.
Why VPN does not work on iPhone: main reasons
iOS is a closed system, and VPN on iPhone works through configuration profiles. Any error in a profile, conflict with another profile, or system restriction can easily break the tunnel — even if the same config comes up without problems on Android and macOS.
VPN profile conflict
iPhone allows only one VPN to be “active” at a time, but several profiles may be installed. If you installed several clients (WireGuard, OpenVPN Connect, third-party “boxed” VPNs), the system sometimes tries to bring up the wrong tunnel. Go to “Settings → General → VPN & Device Management → VPN”, leave one active profile, and delete the others completely — do not just disable them.
On-Demand and Always-On get in the way
On-Demand turns on VPN automatically according to rules (for example, on any Wi-Fi except your home network). If the rule is written incorrectly or points to an unavailable domain for checks, iOS will enter a loop of “connecting → error → trying again”, and the user will simply see that it “does not work”. Always-On VPN set through an MDM profile blocks all traffic until the tunnel comes up — on iPhone this looks like “no internet at all”.
IKEv2 vs WireGuard on iOS
The IKEv2 built into iOS is stable, but in Russia TSPU filtering equipment has long been able to detect its signature — the connection may come up, while packets do not go beyond the provider. WireGuard is not blocked everywhere in Russia and not always in the same way, but on iOS it is more sensitive to MTU: with MTU 1420 on an LTE network, the tunnel comes up but there is no traffic. Lowering MTU to 1280–1380 most often fixes “connected, but does not work”.
After an iOS update
Major iOS updates periodically break third-party VPN clients: Network Extension behavior changes, profile certificates are revoked, and the DNS stack is rebuilt. If the VPN stopped working exactly after an update, reinstall the client from the App Store, delete the old configuration profile, and install it again.
iCloud Private Relay
If iCloud+ Private Relay is enabled, Safari and system requests go through Apple relays, not through your VPN. From the outside, this looks like “the VPN is on, but websites open from a Russian IP”. Disable Private Relay in “iCloud → Private Relay” — or at least for the specific Wi-Fi network.
How to understand what exactly broke on the iPhone
| Symptom | Possible cause | What to check |
|---|---|---|
| The VPN switch turns on and immediately turns off | Broken profile or expired certificate | Delete the profile completely, then install it again from the client |
| Connected, but websites do not open | DNS inside the tunnel or MTU | Specify DNS in the config (1.1.1.1, 8.8.8.8), lower MTU to 1280 |
| VPN drops when switching Wi-Fi ↔ LTE | IKEv2 does not rekey in time | Switch to WireGuard, disable On-Demand while moving between networks |
| VPN turns on by itself and blocks internet access | On-Demand with a broken rule | Turn off On-Demand, check manually |
| VPN works, but the site opens from a RU IP | iCloud Private Relay overrides it | Disable “Private Relay” in iCloud |
| VPN stopped working after an iOS update | Network Extension behavior changed | Update the VPN client from the App Store, reinstall the profile |
How to check right now
Before changing configs, it is useful to understand whether the problem is with your iPhone or whether the website/service is unavailable through your operator in general. Freedom Checker regularly polls popular resources through different operators and protocols and shows where access is currently green and where it is red.
If the needed site opens for your operator on the availability map but not on your iPhone, the cause is almost certainly local (profile, DNS, MTU, On-Demand). If it is red for everyone, this is blocking, and you need to change not the phone settings, but the server or protocol.
Failure or blocking?
A temporary failure looks like this: the VPN does not connect for 5–30 minutes, then comes up by itself. It often coincides with a home router reboot or an LTE cell change. This is fixed by time.
Blocking behaves differently: the VPN connects, but there is “silence” in the tunnel, or it drops exactly 30–90 seconds after the handshake. The symptom repeats every time, on any server from the same provider, and consistently through one operator (for example, Beeline on LTE). This is already TSPU filtering equipment at work — switching protocol (for example, to VLESS over Reality) or using a server in another country helps.
What to pay attention to
- One active VPN profile in the system — not two, not three.
- WireGuard on iOS is more stable than IKEv2 when switching networks.
- MTU 1280–1380 for mobile internet is a working range.
- Set DNS in the VPN config itself; do not rely on “auto”.
- Disable Private Relay if you are working through a VPN.
- After an iOS update, reinstall the client and profile instead of hoping it will work.
- If nothing helps, check the site through another operator in Freedom Checker.
Conclusion
“VPN does not work on iPhone” is almost always a combination of small iOS-specific problems: an extra profile, On-Demand, MTU, Private Relay, or the consequences of an update. Rule them out first, and only then look for a server-side problem.
To avoid guessing, start with a check: is the site you need open through your operator right now? After that, it will be clear what exactly needs fixing — the phone or the tunnel.