When a VPN will not connect in an office, a hotel or on campus, the app is usually not the problem. The network passes only 80 and 443, blocks UDP, or forces DNS to its own server — and each of those is cured by a different protocol. This page checks all four and tells you what will get through here.
Nothing to install; it all runs in the browser.
Press "Check the network" — about seven seconds.
| What the check showed | What will connect here |
|---|---|
| Everything gets through | Any protocol. Take WireGuard — it is faster on weak hardware. |
| UDP closed, 443 works | A protocol over TCP 443: VLESS with Reality or similar. WireGuard and IKEv2 will not connect. |
| A non-standard port does not get through | Only nodes on 443. A config with an unusual port number after the address is useless in this network. |
| DNS does not go outside | The network keeps its own resolver. A connection usually survives that, but names before the tunnel are not resolved by you — see the DNS leak test. |
What is checked are our addresses and public STUN servers, not the particular server you connect to: a network can pass 443 to some hosts and block it to others. UDP is checked on the STUN ports, 3478 and 19302; a network that passes one UDP port and blocks the rest will look closed here. QUIC is not checked separately: HTTP/3 is not enabled on our side yet, and measuring someone else’s would mean passing their rules off as yours.
More on this: who resolves your names, more about UDP and which services do not open in this network.
404 VPN connects over VLESS with Reality on TCP 443 — to a filter that is indistinguishable from an ordinary site. Where UDP is closed and non-standard ports do not pass, it is the only thing that works.
How to connect 404 VPN →Was this useful?
One tap, no sign-up