Mayak Blog

VPN will not connect on MegaFon: what our measurements actually show

On MegaFon mobile data a tunnel either fails to come up at all — a full minute of “Connecting…” — or comes up in a second and runs at full speed. Below are our own measurements taken in Moscow on 28 July 2026: nine profiles in a row, each changing exactly one variable. The question we are asked most often is “does MegaFon block VPN” — here it is answered by a measurement rather than a guess.

In short. On MegaFon mobile data an ordinary profile does not connect at all: no handshake, a full minute of “Connecting…”. Neither the port nor the server address decides it — we tested both by measurement. What decides it is the shape of the first packet: 20 bytes carrying a recognisable signature get through where 1200 random ones do not. With masking the tunnel comes up in a second and runs at 117–127 Mbps. Over IPv6 the same profile comes up even without it.

We build Mayak. The app shapes the first packet to fit the network and walks through the paths by itself — exactly what decides the outcome on MegaFon. 7 days free once you confirm your email, no card required.

What actually happens on MegaFon

A plain profile (port 51820, no mimicry) on MegaFon mobile data does not connect at all: there is no handshake, the app shows “Connecting…” for a minute and gives up. That is different from what we saw on MTS, where the handshake succeeded and traffic died two to three seconds later — the MTS case separately. MegaFon cuts earlier and harder: it never gets as far as a connection.

The very same profile on the very same phone comes up in a second over home Wi-Fi. So it is not the phone and not the settings — why a mobile network behaves differently from a home one.

Port 443 does not help — measured separately

The first advice you will find anywhere is “move to 443, that is where the whole web goes”. We tested it directly: the noise-443 profile differed from the broken one by the port and nothing else.

ProfilePortMimicryResult
baseline 51820no ✗ never connects
noise-443 443no ✗ never connects
quic 443yes ✅ 117 Mbps
quic-hi 51822yes ✅ 127 Mbps, in a second

The reading is unambiguous. Port 443 without mimicry did not help. Mimicry on an ordinary high port 51822 worked, and worked faster than on 443. The port means nothing; what the first packet looks like means everything.

They look at the content of the first packet, not its size

Next question: does mimicry help because it changes the packet size, or because it changes a recognisable signature? One measurement separates the two. The rand-big profile sent 1200 random bytes — exactly as many as the working variant, but with no signature at all.

  • rand-big, 1200 bytes, no signature — does not connect;
  • sip-hi, ~150 bytes carrying a real SIP signature — connects;
  • stun-hi, 20 bytes with a STUN signature — connects, 109 Mbps down, idle jitter 6.

Twenty bytes with a recognisable signature pass where 1200 random ones do not. The filter therefore reads the content of the first packet and is indifferent to its size.

“Does MegaFon block the server address?” — checked by a separate measurement

This is almost everyone’s first guess: perhaps our server is simply blacklisted. We checked that guess directly. From the same phone on the same MegaFon SIM: a plain http:// request to our address does not go through (ERR_TIMED_OUT), while a UDP tunnel to that same address works and pulls over a hundred megabits.

In our measurement — no: one and the same address answers in one kind of traffic and stays silent in another. So what differs is not the address but the shape of the traffic. The practical conclusion: hunting for an “unblocked address” or a different server is pointless — in our runs it never changed the outcome.

Over IPv6 the same profile comes up without mimicry

One more separating measurement: the v6-baseline profile — the very one that never connected over IPv4 — came up over IPv6 in a second and with no mimicry whatsoever. Exactly one thing differed: we reached the server over the sixth version of the protocol. Together with the previous finding, this is why Mayak tries IPv6 first.

What you actually get on MegaFon once it is up

Measurements from a single day, Moscow, 4G+:

  • with mimicry on a high port — 127 Mbps down, 27.9 up, idle ping 71 ms;
  • through our production exit in the Netherlands — 96.9 down, 35.5 up;
  • with no tunnel at all (control) — 139.5 down, 20 ms latency.

The drop from 139 to 97 is the price of the leg to the Netherlands and back, not throttling. ⚠️ And one caveat that cost us a whole investigation: on a mobile network a single measurement proves nothing. Two consecutive runs on one tunnel that day returned 2.91 and 41.98 Mbps — why speed tests show different results.

“It will not connect” on mobile data and on Wi-Fi — in numbers

“MegaFon will not let me connect”, “it stopped working” — that is how people usually describe it. To see how common it is, we counted our own connection log over 30 days (measured 5 September 2026): from mobile data 88.8 % of attempts succeed (309 of 348), from Wi-Fi — 94.8 % (257 of 271). A cellular network really is harder than a home one — and still, on it a connection stands up nine times out of ten.

Hence a fork that saves you an evening. If the same connection comes up over Wi-Fi but not over mobile data, you are in exactly the case described above: it is the shape of the first packet. If it stopped working everywhere, Wi-Fi included, the cause is a different one and it is not in the operator’s network — most often it is the single VPN slot inside Android itself, and almost nobody checks it.

⚠️ These numbers come from our own users and our own app over a single month, and our own devices are in that log too. It is an order of magnitude, not national statistics. The general picture across networks — why VPN fails on mobile data but works on Wi-Fi.

What to do when MegaFon will not connect

  1. Do not change the port. The measurement above shows it does not cure anything.
  2. Check whether it comes up over Wi-Fi. If Wi-Fi works, the problem is the mobile network, not your phone and not your account.
  3. Let the app walk its ladder. Mayak tries the paths itself and shows which one you are on — how that works.
  4. Make sure the connection is genuinely up. A “connected” badge proves nothing — four checks in a minute.

Mayak does this by itself. The app shapes the first packet to fit the network and walks through the paths until the connection stands up — exactly what decides the outcome on MegaFon. We never ask for payment details. A confirmed email opens the access — 7 free days.

Short answers

Does MegaFon block or throttle VPN? In our measurement it was neither the address nor the port: plain HTTP to the same server did not go through, while a tunnel with mimicry to that very server pulled over a hundred megabits. What decided the outcome for us was the shape of the first packet.

MegaFon blocked my VPN — what should I change in the settings? Of the things we actually measured: changing the port is useless, mimicry helps. In Mayak mimicry is on by default, and “Settings” → “Check connection” takes a minute to show which path is the one failing for you — instead of guessing.

VPN stopped working on MegaFon — why today? What the operator changed and when, we do not know and will not invent. What we do have is the check that separates the causes: try the same connection over Wi-Fi. Works on Wi-Fi — it is the cellular network; works nowhere — the cause is in the phone and is covered separately.

Which VPN client does MegaFon support? Judging by our measurements the question is aimed at the wrong thing: what passed or failed for us was not a “client” but a specific shape of the first packet — 20 bytes with a recognisable signature passed where 1200 random bytes did not. We do not compile lists of other people’s apps: about ours we say what we measured, and we did not measure theirs.

How do I connect a VPN on MegaFon? With Mayak — install the app, create an account and press “Connect”: mimicry is on from the start and the app walks the paths itself — how that walk works. There is nothing to configure separately.

Do your numbers hold everywhere? No. The nine profile runs were measured IN MOSCOW in late July 2026, and the success rate comes from our own log for the 30 days up to 5 September. In another city and another month the picture may differ — which is why we always say where and when we measured.

Short version: on MegaFon what decides is the shape of the first packet. Port, packet size and server address were each checked by a separate measurement and none of them changes the outcome.

Try Mayak

Our own servers in the Netherlands, Poland and Russia, an honest label showing which route you are on, and measurements we publish as they came out. 7 days free once you confirm your email, no card required.

The account is created right in the app. A confirmed email opens the access — 7 free days.