“Won’t connect” covers at least four different cases: endless connecting spinner, connected badge with no traffic, frequent drops, or hard errors about accounts or certificates. Treating them the same leads to endless reinstalls. This article maps symptom → cause → action. Keep the download page handy to confirm your client version matches the latest package notes.
Spend one minute on an environment snapshot: Wi‑Fi vs cellular, corporate or campus network, automatic time enabled, other VPN or proxy tools running. Those answers tell you whether to change nodes or change networks entirely. For install and permission basics, see the install guide and guides hub.
Symptom → fix quick reference
| What you see | Likely cause | Try first |
|---|---|---|
| Connecting > 60 seconds | Busy node; UDP filtered | New city; switch to TCP |
| Connected, no traffic | Split rules; DNS; VPN clash | Global mode; disable other VPN; flush DNS |
| Drops after seconds | Battery saver; weak signal | Unrestricted battery; auto-reconnect |
| Account/certificate error | Expired plan or profile | Renew; refresh iOS profile |
| Single app fails | Split tunnel; app blocks VPN | Adjust routing; disconnect for that app |
| All nodes fail | Local network; time; firewall | Phone hotspot test; sync time |
Step 1: Rule out local network
Many “broken VPN” reports are really captive portals or outbound filtering. Tether LTE/5G on the same phone and retry. If cellular works instantly, fix the original Wi‑Fi or broadband path—not the client.
System time
TLS breaks when clocks drift. Enable automatic time on Windows, macOS, iOS, and Android. Errors like invalid certificate or endless connecting often trace to minutes of skew.
DNS and captive portals
Hotels and airports require browser login before tunnels work. Complete the portal page first. If only HTTPS fails after connect, try public DNS (e.g., 1.1.1.1) inside the client or OS for a quick test.
Firewalls and endpoint security
Third-party antivirus, EDR, or Little Snitch-style filters may block the VPN process. Temporarily allowlist Kuaimiao. Managed corporate laptops with TAP restrictions may never establish a tunnel—use a personal device instead.
Step 2: Nodes and load
Latency in the list is a snapshot, not a SLA. Peak hours can push a usable node from 80 ms to 300 ms yet still work—or a “green” node may be down for maintenance.
- Try three different countries/regions, not just the first row.
- Avoid nodes marked high load if the UI shows it.
- Use streaming or gaming labeled lines for video if available; standard nodes suffice for browsing.
- Relying on one favorite node makes every outage feel like an account ban—rotate occasionally.
Auto-select fastest can help when healthy; when it fails, manually pick a nearby region.
Step 3: Protocol and ports
Advanced settings usually expose Auto, UDP, TCP, and sometimes obfuscated or TLS-like modes depending on build.
| Scenario | Suggested protocol | Why |
|---|---|---|
| Home broadband | Auto or UDP | Lower latency |
| Office/campus Wi‑Fi | TCP or TLS-style | UDP often filtered |
| Public Wi‑Fi fails | TCP + new node | Portal + UDP limits stack |
| Connected but slow | Change node first | Load beats protocol tweaks |
After changing protocol, disconnect and reconnect—some builds ignore dropdown changes until you do. Do not stack system proxy, browser extensions, and global VPN unless you enjoy DNS chaos.
Step 4: Account, plan, and devices
Immediate “invalid account,” “expired,” or “device limit” messages are account issues—nodes will not help.
- Expired: Renew with your seller; sign out/in or restart the client.
- Password: Watch copied spaces; case sensitivity matters.
- Device cap: Remove old phones, emulators, or idle tablets in device management.
- Abuse lock: Rapid geo hopping or shared logins may need vendor support.
The FAQ summarizes billing and source questions—do not paste random “free node” URLs into the client.
Step 5: VPN permission and conflicts
Android
If you ever denied VPN setup, delete stale entries under Settings → Network → VPN or reinstall and allow the prompt. Work profile VPNs are separate from personal space—install where you actually use the app.
iOS / iPadOS
Settings → General → VPN & Device Management should list only active profiles. Expired profiles may still show old servers inside the app—follow updated steps on the download page.
Windows
Remove unused VPN connections under Settings → Network & Internet → VPN. Yellow-bang TAP adapters from old products may need removal and reboot. Hyper-V virtual switches occasionally clash—test with VMs off.
macOS
System Settings → Network: ensure Kuaimiao’s extension is enabled. After OS upgrades, re-approve disabled extensions in Privacy & Security. Menu bar VPN icon with no traffic often means the extension never loaded—restart app or Mac.
Routing modes and fake connects
Smart split, bypass lists, and rule-based routing decide which traffic enters the tunnel. Stale rule sets produce the worst outcome: foreign sites fail while local apps also lag.
Switch to global mode for thirty seconds as a diagnostic. If global works, the tunnel is fine—fix rules or DNS split instead. Kill switch cuts all internet when VPN drops; do not confuse that with “cannot connect.”
Platform thirty-second checks
| Platform | Quick check |
|---|---|
| Windows | Firewall allow; no stale TAP; auto time |
| Android | VPN permission; battery unrestricted; split rules |
| iOS | Single VPN profile; profile not expired; Low Power off |
| macOS | Extension approved; no manual HTTP proxy |
When reinstall helps—and when it does not
Reinstall makes sense: interrupted install, blank UI after upgrade, confirmed wrong package now removed, missing VPN permission prompt ever.
Skip reinstall: single node failure, office Wi‑Fi only, expired account, expired iOS profile. Download the latest build from the download page only after logical fixes fail.
Still stuck: information to gather
Support tickets move faster with:
- Platform and OS version (e.g., Android 14, Windows 11 23H2).
- Client version from About.
- Exact error text or redacted screenshot.
- Nodes, protocols, and networks already tried.
- Whether the issue started after OS upgrade or plan expiry.
Avoid sending passwords or SMS codes to unofficial “tech support.”
Connection failures are common and usually narrow to network, node, or protocol choices. Walk the symptom table top to bottom before wiping the app. Remember: “Connected” only means the tunnel object exists—not that DNS, split rules, and your account are all healthy. Separate those layers and you will beat reinstall roulette.
Router and ISP-level quirks
Some home routers ship with “VPN passthrough” disabled or aggressive UDP flood protection. If every device on Wi‑Fi fails while cellular works, log into the router admin UI and look for IPS, parental control, or gaming QoS features that inspect packets. Temporarily disable them for a five-minute test—not as a permanent fix, but to learn whether the bottleneck is inside your house.
ISP DNS hijacking can produce “connected but search redirects to ads.” Switch DNS inside the client or OS during testing. Satellite or maritime links with high jitter may drop UDP quickly; TCP or TLS-style modes trade speed for stability on those links.
Travel and restrictive networks
Airport lounge Wi‑Fi often allows general browsing but throttles long-lived VPN sessions. Connect after the captive portal, pick TCP, and expect to re-auth after sleep. Hotel networks that charge per device may count VPN tunnels as extra MAC addresses—read the hotel splash page before blaming the client.
In countries or campuses with explicit VPN blocking, no client setting guarantees access; legal and policy constraints come first. This guide assumes you are allowed to use the service on your network. When blocked, document the exact error for your vendor rather than cycling dozens of nodes in minutes, which can trigger abuse systems.
Performance tuning without breaking stability
After stability returns, you may tune for speed: prefer geographically closer nodes for daily browsing, reserve distant nodes for specific services, and avoid flipping protocols every few seconds. Let a configuration run at least thirty seconds before judging it—immediate disconnects differ from slow page loads.
Streaming and gaming benefit from consistent routing. If smart split rules include outdated domains, update the rule source or fall back to global mode during the show, then revert afterward. Document what worked; next time you connect on the same hotel Wi‑Fi, you will not repeat a twenty-minute blind search.
Logging and privacy-conscious diagnostics
When opening a ticket, you may be asked for connection logs. Export only what support requests and redact account identifiers. On shared machines, delete exported logs after the case closes. Turning on verbose debug modes can slow the client—enable them only during active troubleshooting, then switch back to normal logging so battery and disk use stay predictable.
If your organization forbids uploading logs to third parties, describe symptoms in text instead: timestamp, node country, protocol, and whether a phone hotspot succeeded. That narrative often replaces raw files while respecting workplace policy.