Offices, campuses, hotels and some carriers drop UDP. Then WireGuard and IKEv2 fail to connect while TCP-based protocols keep working. Let us check what the network you are on right now allows.
Press the button; it takes about six seconds.
The browser asks STUN servers (Google, Cloudflare) to reply over UDP. A reply means UDP passes and WireGuard will very likely connect. No reply while local addresses were found means the network drops UDP, and you need a TCP-based protocol.
In your VPN app pick VLESS (it runs over TCP 443 and looks like ordinary HTTPS) or turn on automatic protocol selection. Background in what is VLESS and VPN not working on Wi-Fi.
It probes the STUN ports (3478 and 19302), not your VPN server's port. A network may allow one UDP port and drop another, so WireGuard on a non-standard port occasionally still works. Nothing is sent to our servers.
404 VPN switches between WireGuard and VLESS + Reality by itself: where UDP is closed, the tunnel goes over TCP 443 and looks like a regular website.
How to connect 404 VPN →