Is It the Client or the Provider? A Diagnostic Workflow
Use cross-testing across nodes, clients and networks to isolate the problem.
Step 1: Change one thing at a time
Record the current state and change a single variable. Do not switch TUN, DNS, routing mode, IPv6 and rule sets all at once.
Step 2: Identify the scope
Ask: Do all nodes fail? Does only one client fail? Does the problem remain on another network? These answers quickly narrow the cause.
Step 3: Cross-test
- Try another node.
- Update the client profile.
- Use direct mode to test local connectivity.
- Try another compatible client when necessary.
- Read logs instead of relying on the connected/disconnected icon alone.
Step 4: Diagnose by layer
Client layer
Check version, configuration format, permissions and whether multiple clients are running.
Network layer
Check Wi-Fi/Ethernet, DNS, IPv4/IPv6 and firewall behavior.
Endpoint layer
Compare several nodes. A single failed node should not immediately be blamed on the client.
Provider layer
If multiple clients and nodes fail together, check provider status, subscription validity and usage limits.
Common conclusions
Only the browser fails: inspect browser proxy settings, extensions and DNS.
Browser works but a desktop app fails: check system proxy and TUN.
Every device fails: investigate the service, subscription or network path.
Only one node fails: the endpoint may be the problem.
Keep a troubleshooting record
Record the client, node, network, routing mode and DNS state. This makes repeated diagnosis much faster.