You tap “Connect” and one of three things happens: the toggle lights up and flips straight back off, “Connecting…” hangs forever, or an error appears. It looks like one fault, but a connection goes through five steps and can break at any of them — and each step fails in its own recognisable way.
In short. Try once more first: in our journal for 3–8 September, out of 91 failed attempts 60 were followed by a successful attempt by the same person, so there was nothing to fix. If that does not help, read the sign. The toggle dies within a second — it is the phone: the system permission was not granted, or another app is already holding a tunnel. “Connecting…” hangs for tens of seconds — the handshake is not reaching the server; switching network, country or forcing the backup channel helps. An instant error — usually expired access or an outdated build. The full order takes about a minute and is at the end of this article.
We make Mayak. Four routes to the server instead of one, switching between them without the human, and an honest label showing which route you are on. 7 days free once you confirm your email, no card required. The trial is free and needs no card; without an email it is 3 days.
🍎 On iPhone Mayak works through the third-party Happ app — with the subscription link from your account. Happ is not in the Russian App Store; there incy (publisher LLC ITDEV) works instead, checked on 22 September 2026.
What happens after you tap “Connect”
“Connecting” is not one action but a chain. The steps run strictly in order, and each one starts only when the previous has finished — which is why how it broke usually tells you where it broke.
| Step | What happens | How the failure looks |
|---|---|---|
| 1. System permission | Android asks whether the app may carry all of the phone's traffic | The toggle dies within a second, no key icon in the status bar |
| 2. Talking to the access server | Over an ordinary secure connection the app asks who you are and what you have paid for | An almost instant error: “no access”, “sign in again” |
| 3. Handing out the settings | The server returns the keys and the address of the node to connect to | Instant error; the account page shows the access has expired |
| 4. Handshake with the node | Phone and server exchange their first packets and agree on encryption | “Connecting…” hangs for tens of seconds and gives up |
| 5. Bringing up the routes | The system points traffic into the tunnel and assigns DNS | The icon is lit, but nothing loads |
Step four is where the network gets involved: everything before it happens inside the phone and over an ordinary secure connection, and here the tower, the operator's network and the equipment that inspects traffic all get a say. So “connecting hangs” is almost always a conversation about the network, and “dies instantly” is almost always a conversation about the phone.
If it got as far as step five — the icon is lit but nothing loads — that is a different fault, covered separately: the VPN connects but there is no internet.
The toggle turns on and immediately off
The commonest case, and the connection breaks on step one — it never reaches the network at all. Causes, most frequent first.
- The system permission was not granted. Android shows the “Connection request” dialog once; tap “Cancel” (or let it close itself) and the tunnel will not come up. Tap connect again and confirm the dialog.
- Another app already holds the tunnel. Android allows only one active VPN connection at a time. The second app either fails to start or kicks the first out — and if the other app has “Always-on VPN” enabled, it will keep taking the connection back. Check Settings → Network & internet → VPN and turn off “Always-on VPN” for anything you do not use.
- The permission was taken away. It is dropped when the app is removed, when “optimiser” tools clean the phone and sometimes on a system update. The sign: it used to work and you changed nothing.
- The app was put to sleep to save battery. Then the tunnel comes up and dies minutes or hours later — a neighbouring picture, covered separately, with the settings.
“Connecting…” hangs and nothing happens
A break on step four: the app sends its first packet and gets no answer. Waiting longer does not help — if the handshake did not come together within seconds, it will not come together in a minute either; the app simply retries.
The thing to understand here is that “nobody answered” and “somebody refused” look identical from the phone. Between you and the server there is a tower, the operator's network and equipment that inspects traffic; any link can drop one particular flow and pass the next one happily. A weak signal in a lift looks exactly like a filter.
Hence the first action — simply try again. We counted it: the app records every connection attempt and whether it succeeded.
| 91 failed attempts, 3–8 September 2026 | Count |
|---|---|
| The next attempt by the same person succeeded | 60 |
| …over the same direct route, no backups | 45 |
| …needed the backup channel | 15 |
| The next attempt failed too | 30 |
| The person did not try again | 1 |
Read it like this: almost two thirds of the failures went away on the second attempt, with not a single setting changed. The same numbers in full are in the article about “it worked yesterday”.
If a second attempt does not help, what decides is not patience but a change of conditions: another network, another country, another way of connecting. For that the app needs more than one route to the server, and it should switch between them by itself — how that works here. In our journal for 3–8 September 61 successful connections out of 580 attempts went over the backup channel (10.5 %, against 2.1 % two weeks earlier) — for every tenth connection the direct route simply would not do.
An error right after the tap
A fast refusal with a message means step two or three: the phone did reach the access server and got a clear “no”. Three usual causes.
- The paid or trial access has run out. The fastest check of them all — thirty seconds in the account page. The sign: no country connects, and it fails instantly rather than after long attempts.
- You are signed out. The app asks you to sign in again; access lives in the account on the server, not in the phone, so the keys are re-issued by themselves.
- The build is old. Ways of connecting change along with the network, and an old app often knows exactly the one that stopped getting through. The sign: it works for a friend on the same service, not for you.
“I paid — why will it not connect?” Paying does not buy passage: the equipment on the way does not know or care whether you paid. What the money does buy is covered in a separate article.
Connects on Wi-Fi but not on mobile data (or the other way round)
The most useful sign of all, because it splits the causes in half at once: if the tunnel comes up on one network and not on another, it is neither the phone nor the service — it is the network. So test exactly that: turn on mobile data instead of Wi-Fi and try again.
From there the analysis goes by network — we have measurements for mobile operators and for home internet and Wi-Fi, and for individual networks — Megafon, MTS, Beeline, Tele2 and Yota.
A one-minute order of actions
Most frequent first; after each step simply try to connect.
- A second attempt. Ten seconds, and by the table above it closes two thirds of the cases.
- Check whether another app holds the tunnel. Settings → Network & internet → VPN: one active connection per phone is the system's rule, not our app's.
- Look at your account page. Thirty seconds, and “has my access run out” is answered by a number instead of a guess.
- Update the app. Free, and often fixes everything.
- Switch between Wi-Fi and mobile data. Not a random shot but a way of separating causes.
- Change the country. Routes to different countries differ: what will not pass to one often passes to another.
- Force the backup channel. If the direct route never gets through on your operator, there is no point waiting for the ladder — in our app it is the “Always use the backup channel” switch.
If there is still no connection after all that, it is worth running four checks in a minute: they show which step exactly is breaking, and without them any support conversation turns into guesswork.
What we do not know
The most important part, and we would rather say it ourselves.
- We have no measurement of “which step failed”. The journal records which route worked, not why the previous one did not. The breakdown above is how a connection is built, not a statistic of failures, and we will not pass it off as one.
- The numbers are small. 27 people in the 3–8 September window. A sample like that can explain a mechanism; it cannot measure a country.
- “Next attempt” is blind to those who left. Anyone who gave up and deleted the app makes no next attempt and never enters the denominator — so the measure errs in our favour. The only thing that softens it is that 90 of the 91 failures did have a next attempt — only one was left with no second try at all.
- We only see our own users. Our journal knows nothing at all about what happens to people on other services.
- This is a 10 September snapshot. Connection reports sometimes reach us late, so the same window counted on the evening of 8 September came out nine attempts short. The neighbouring articles carry the same numbers.
Short answers
Why will my VPN not connect? Read the sign: dies instantly — the system permission or another app holding an active tunnel; “Connecting…” hangs — the handshake is not coming together, so change network, country or force the backup channel; an instant error — expired access, a signed-out account or an old build.
Why does the VPN toggle switch itself off? On Android only one VPN connection can be active. If another app is holding it — especially with “Always-on VPN” enabled — yours will keep dying instantly. What to check.
No VPN connects at all, not one service. Then the cause is not in the app, and the analysis is different — why not a single VPN connects.
It connects, but slowly. That is not a failure but the ladder: the app tries its routes in turn. How long it takes and what speeds it up — in a separate article.
I paid and the VPN will not connect. Paying does not buy passage through a filter. Check the access dates in your account, then read the article about paid access.
How many times should I retry before changing anything? Two or three. In our journal 60 failures out of 91 were closed by the very next attempt; if the third does not go through either, what helps is changing conditions, not patience.