VPN connection stability doesn’t depend on a single protocol but on the whole chain: the network your device is on, the transport (UDP or TCP), how far away the server is, and a few settings such as MTU and DNS. Here is what affects the connection, how to choose a protocol for your network, and what to do if the connection keeps dropping.
The guide is practical and formula-free. It explains why a VPN can run smoothly at home and drop on mobile data, how UDP differs from TCP, what the MeduzaVPN app does automatically, and which steps are worth trying in order.
What stability depends on
A VPN tunnel runs on top of an ordinary network and inherits all its quirks. If the network loses packets, is congested or switches often, the tunnel feels it first. Below are the main factors, how they show up and what usually helps.
| Factor | How it shows up | What helps |
|---|---|---|
| Packet loss | Video and calls freeze, speed drops, the connection breaks | A loss-tolerant protocol: ULTRA, or Hysteria where UDP is open |
| Latency | Pages and apps respond slowly | A location closer to you |
| Network change | A short drop when moving from Wi‑Fi to mobile data or between cells | Automatic connection recovery |
| Channel load | Speed jumps around at peak hours and on public Wi‑Fi | Another network or location, split tunneling |
| Unstable UDP | UDP protocols connect but keep dropping | A protocol with TCP transport, such as VLESS |
| MTU | The tunnel is up, but large pages and files load with difficulty | Automatic MTU selection in the app, or lowering it manually if needed |
| DNS | The tunnel is up, but sites don’t open by name | The “DNS through VPN” setting |
Network quality: loss, latency, load
Packet loss is the main enemy of a stable tunnel. When some packets don’t arrive, the protocol spends time resending them, speed drops, and video and calls freeze. The source of the loss is almost always in the network between the device and the server: a weak signal, an overloaded access point, a busy segment at the provider.
Latency affects how responsive the connection feels, and speed too: the higher it is, the more slowly a TCP connection ramps up. More on speed in the article why a VPN is slow.
Wi‑Fi
Home Wi‑Fi is usually the most stable environment, but it has weak spots too: walls and distance to the router, neighbouring networks on the same channel, many devices at once. On public networks — in hotels, airports and cafés — dozens of people share the channel, and speed jumps around noticeably. If the VPN is unstable in only one place, the cause is most often that network.
Mobile data and cell handovers
A mobile network is less stable than a home one: latency is higher and jumps around, packets are lost more often, and UDP traffic can be patchy. On the move, the phone switches between base stations, and at home between Wi‑Fi and mobile data. At those moments the device’s address changes and the tunnel has to be re-established. Protocols designed for these transitions do it without the user noticing.
UDP and TCP
Every VPN protocol carries data over a particular transport. That determines how it behaves on a given network.
- UDP doesn’t wait for every packet to be acknowledged, so it’s faster and well suited to a tunnel. WireGuard, the MeduzaVPN protocol and Hysteria run over it.
- TCP delivers data with acknowledgements and retransmission. It reacts more slowly to loss but connects on networks where only TCP is open. VLESS, OpenVPN in TCP mode and SoftEther run over TCP.
- Port 443 is the standard HTTPS port. TCP transport on this port usually connects more reliably on corporate and hotel networks with strict settings.
The practical takeaway: if a UDP protocol keeps dropping on your network while a TCP protocol runs smoothly, UDP is unstable on that network. Keep as your main option whichever one behaves better where you connect most often.
MTU and DNS
MTU
MTU is the maximum packet size that can travel along the path without being split. A VPN adds its own headers to every packet, and if the MTU inside the tunnel is too large, big packets get fragmented or lost. The connection looks fine, but heavy pages and files load with difficulty. The app picks the MTU automatically, and on networks with non-standard settings lowering it manually helps.
DNS
If the tunnel is up but sites don’t open by name, DNS is the most likely cause: name lookups don’t get through or skip the tunnel and go to your provider’s DNS server. Turn on “DNS through VPN” in the settings — then name resolution also goes through the protected connection.
Location distance
The farther away the server, the longer the route and the more intermediate hops on it, each of which can add latency or loss. For everyday use it’s usually best to pick a location close to you: the connection will be smoother and responses faster.
You can pick a location from the list of servers. If the route to the current data centre in particular is unstable, moving to another location helps, or “Change IP” in your account: your personal VPN will move to another server in the same location with a new address.
How to choose a protocol for your network
A MeduzaVPN personal server runs every protocol at once, so you don’t have to choose once and for all — you can choose for a specific network. Rough guidelines:
- By default — MeduzaVPN ULTRA. MeduzaVPN’s own protocol, built for a stable, fast connection. It’s designed for unstable and congested networks, restores the connection by itself, and its speed stays close to WireGuard.
- Home Wi‑Fi and a router on a stable network — the MeduzaVPN protocol or WireGuard. Both run over UDP, are fast and efficient, and WireGuard handles the switch from Wi‑Fi to mobile data quickly.
- Unstable UDP — VLESS. It runs over TCP with TLS and usually connects more reliably where UDP protocols keep dropping.
- A channel with packet loss — Hysteria. It runs over QUIC and holds speed well on unstable channels, as long as UDP is open on the network.
- A network where only TCP on port 443 is open — VLESS, SoftEther or OpenVPN in TCP mode. This is common on corporate and hotel networks.
A detailed comparison of all protocols is in the article VPN protocols in 2026.
What the app does
The MeduzaVPN app takes care of most of the stability work; you only need to choose a protocol and a location.
- Restores the connection automatically. ULTRA reconnects by itself after a drop or a network change, with no manual setup.
- Switches protocols without reinstalling. MeduzaVPN ULTRA, MeduzaVPN, WireGuard, OpenVPN, VLESS, V2Ray, Xray, Shadowsocks, Outline, Hysteria, SOCKS5, IKEv2 and SoftEther run on one server, and switching protocol doesn’t require signing in again.
- Keeps a kill switch. While the tunnel reconnects, traffic doesn’t go out directly.
- Supports split tunneling. Split tunneling lets you take services that don’t need a VPN out of the tunnel and lighten the load on the connection.
What to do if the connection is unstable
- Switch the protocol. Start with ULTRA; if UDP is unstable on your network, try VLESS, and on a channel with loss where UDP is open, try Hysteria.
- Pick another location. The one closest to you usually gives a smoother connection.
- Press “Change IP”. Need a new address or another server in the same location? You can do it in your account.
- Check on another network. That makes it easier to tell whether the issue is the network or the device settings. If the VPN doesn’t connect at all, follow the steps in the article VPN not connecting.
- Contact support. They can see your server’s status and will suggest what to try next.
Honest limits
- There are no guarantees. A VPN runs on top of your network and can’t make it better than it is. A promise of “100% stability” is misleading; the realistic promise is a set of protocols and fast switching between them.
- A protocol can’t fix a weak signal. If mobile data or Wi‑Fi loses connection, the tunnel will drop along with it.
- UDP protocols won’t connect where UDP is closed. Those networks need TCP transport.
- A distant location means higher latency. That’s a property of the route, not a fault of the server.
Conclusion
VPN stability comes from network quality, the protocol’s transport, the distance to the location and correct MTU and DNS settings. There is no universal protocol, so the real value is having every protocol on one server, automatic connection recovery and fast switching in the app.
MeduzaVPN gives you a personal server with its own IP in 60+ locations and the full set of protocols, including ULTRA. Subscriptions come with 7 days free — enough to check which option works best on your network. See plans.
FAQ
What does VPN connection stability depend on?
First of all, on the network you connect through: packet loss, latency, how busy the channel is and how often the device switches between networks. Next come the protocol and its transport (UDP or TCP), how far away the chosen location is, and the MTU and DNS settings. A VPN encrypts your traffic but cannot make the underlying network better, so the same protocol can behave differently at home, on mobile data and in a café.
Why does the VPN drop on mobile data?
A mobile network is less stable than a home one: latency is higher and jumps around, packets are lost more often, and UDP traffic can be patchy. When the phone moves between cells or from Wi‑Fi to mobile data, the device’s address changes and the tunnel has to be re-established. Protocols designed for these conditions handle it noticeably better than classic ones.
Which protocol should I choose for a stable connection?
Start with MeduzaVPN ULTRA — it’s the one the app picks first. It’s designed to stay stable on unstable and congested networks and restores the connection by itself. If UDP is unstable on your network, try VLESS over TCP. For home Wi‑Fi and routers on a stable network, the MeduzaVPN protocol and WireGuard work well; for channels with packet loss where UDP is open, try Hysteria.
How do UDP and TCP differ for a VPN?
UDP doesn’t wait for every packet to be acknowledged, so it’s faster and better suited to a tunnel, but on networks where UDP is unstable the connection can drop. TCP delivers data with acknowledgements and retransmission: it reacts more slowly to loss, but it connects where only TCP is open. That’s why it’s useful to have protocols of both kinds on the server.
Does the connection restore itself?
Yes. MeduzaVPN ULTRA restores the connection by itself after a drop or a network change, with no manual setup. The kill switch in the app keeps traffic from going out directly while the tunnel reconnects.
Will changing the location or using “Change IP” help?
Changing the location helps when latency to the server is high or the route to the data centre is unstable: the location closest to you usually gives a smoother connection. “Change IP” in your account moves your personal VPN to another server in the same location with a new address; the old address is released and can’t be restored. Switching the protocol on the same server doesn’t change the address.
What should I do if the connection stays unstable?
Switch the protocol in the app, then try another location or “Change IP”. Check how the VPN behaves on a different network — that makes it easier to tell whether the issue is the network or the device settings. If that doesn’t help, contact support: they can see your server’s status and will suggest what to try next.
