A VPN for China is a before-you-fly decision, not an on-arrival one. Three things make it different from a VPN anywhere else. The law: China requires international connections to go through state-approved channels, and unapproved VPN services are filtered, though enforcement targets sellers far more than travelers. The technology: the national filter recognizes classic protocols such as OpenVPN and WireGuard by their traffic pattern, so they often never connect, while protocols that look like ordinary HTTPS hold up better. And the logistics: app stores and VPN websites are usually unreachable from Chinese networks, so whatever you have not installed and tested at home, you will not get on the ground.
Nobody can promise a VPN will work from every Chinese network on every day. Filtering rules change, and they tighten around major events. What follows is the honest version: what you can control, and what you cannot.
What the law says
China's rules on international networking require that connections abroad use the state's international gateways; using unapproved channels is a violation. In practice the attention goes to people who sell and distribute VPN services inside the country. Individual users have occasionally been fined, according to press reports over the years, but there is no pattern of enforcement against tourists, and nobody inspects phones at hotels or airports. The decision and the responsibility are yours; this is not legal advice. A broader country list is in Is a VPN legal?.
One thing the filter never touches: roaming. If your data exits to the internet in your home country, which is what happens on international roaming and on most travel eSIMs, Chinese filtering does not apply and you do not need a VPN to reach your usual apps. How that works is explained in eSIM, roaming or a local SIM in China.
Why "my VPN won't connect" is the normal outcome
The national filter does more than block addresses. It inspects traffic and identifies protocols by their signature: packet sizes and order in the handshake, characteristic headers, connection behavior. OpenVPN and WireGuard have recognizable signatures, so the connection either never completes or drops after a few minutes, and the app just shows "connecting".
Protocols designed to be indistinguishable from an ordinary HTTPS session with a real website behave more reliably. VLESS with the Reality extension is the common example: to the filter, the tunnel looks like a TLS session with a legitimate domain, and there is no formal reason to interrupt it. How it works is in What is VLESS and Reality. This is not invisibility and not a guarantee. It is a better bet than the classics, and it should be your primary option with a second protocol or server as backup.
Do everything at home
Three practical reasons. VPN websites are usually unreachable from Chinese networks, so there is nowhere to download an app or a configuration file. The Chinese App Store carries no VPN apps, and changing your Apple ID region on the ground requires a payment method from another country. And testing is far easier where the internet is normal and you have time.
The minimum: app installed, signed in, two different protocols or two different servers configured, connection verified on the What Is My IP page, and the WebRTC and IPv6 leak tests clean. If the app can export its configuration, save a copy in your notes and in cloud storage.
What else affects the connection
The network. Mobile data and hotel Wi-Fi can be filtered differently. If one does not connect, try the other.
The server. Locations close to China, such as Hong Kong, Singapore and Japan, give the lowest latency, but the filter may treat individual addresses differently. Keep two or three options.
The date. Filtering traditionally tightens around national holidays and major events. If a working connection stops "for no reason", waiting and switching servers often resolves it.
The kill switch. At home it protects you: when the tunnel drops, traffic does not fall back to the open network. In China the same behavior can look like "the internet is gone". If things stop working, check whether the kill switch is the cause, and enable it deliberately once the connection is stable. What it does is in What is a VPN kill switch.
What a VPN in China does not do
It does not speed up hotel Wi-Fi. It does not help when the network refuses to establish a tunnel at all. It does not replace WeChat and Alipay: payments, taxis and deliveries in China run inside local apps, and those work without any VPN. And it does not make you anonymous: the carrier sees an encrypted connection, and websites still see your browser.
If nothing connects on arrival
- Switch protocol, for example from WireGuard to VLESS.
- Switch server to another country.
- Move between Wi-Fi and mobile data.
- Turn off the kill switch and confirm ordinary internet is back.
- Turn on roaming for a few minutes: enough to message home and download an updated configuration if your provider issued one.
If none of that works, it is not necessarily your mistake; on some days very little connects. Roaming remains the one dependable fallback on those days.
404 VPN offers VLESS and WireGuard in one app for iOS, Android, Windows and macOS, resolves DNS inside the tunnel, includes a kill switch, and has locations in Hong Kong, Singapore, Japan and Thailand. The free plan, 5 GB a day on one device, is enough to run every check above before you fly. We do not promise availability from every network in China, and we recommend setting everything up at home. Details on the home page.