Last updated: July 2026. Written by Morgan Logan.
Setting up a VPN on any device takes 3-5 minutes if you follow the right steps. This guide covers Windows 11, iPhone/iOS, Android, macOS, and router-level setup, plus how to verify the VPN is actually working after installation. No affiliate recommendations -- this guide works with any reputable VPN provider.
A VPN setup on modern devices requires four steps: download the app from the provider's official website or app store, create an account or log in with existing credentials, choose a server location, and connect. The VPN is active when the connection indicator appears in the app and your IP address changes to the VPN server's IP. To verify setup is correct, visit ipleak.net with the VPN connected -- if your real IP address appears, the VPN is not routing traffic correctly. On iOS specifically, the kill switch requires enabling the always-on VPN profile in iOS Settings after installing the app. On Windows, the system-level kill switch (if separate from the app kill switch) must be enabled manually in the VPN app settings. Most VPN providers use WireGuard as the default protocol in 2026, which is the recommended choice for speed and reliability on all consumer devices.
What You Need Before Setting Up a VPN
Before installing:
- A subscription to a reputable VPN provider. For recommendations with specific test results, see our best VPN 2026 overview. For the privacy-first option, see our Mullvad review. For the best balance of features and price, see our NordVPN review.
- Your account credentials. Username and password (or for Mullvad, your 16-digit account number).
- The official app download page. Go to your VPN provider's official website, not a third-party download site. Third-party downloads can include modified or malicious versions.
One decision to make before installing: which protocol to use. WireGuard is the correct default in 2026 for consumer devices. It is faster than OpenVPN and more reliable than IKEv2 on mobile networks that switch between Wi-Fi and cellular. Your VPN app will likely default to WireGuard or automatically select the best protocol -- leave this setting alone unless you have a specific reason to change it. See our VPN protocols guide for when OpenVPN or IKEv2 make sense.
How to Set Up a VPN on Windows 11
Method 1: Using the VPN provider's app (recommended)
- Go to your VPN provider's official website and download the Windows app.
- Run the installer (you will need administrator permissions).
- Open the app and log in with your credentials.
- The app will default to the fastest or nearest server -- click Connect.
- Verify the connection: the app will show a 'Connected' status and display the VPN server's IP. Confirm at ipleak.net that your real IP is no longer visible.
Kill switch: In your VPN app settings, find the kill switch option and enable it. Most providers call it 'App Kill Switch' (cuts only specified apps on VPN drop) or 'System Kill Switch' / 'Internet Kill Switch' (cuts all traffic). Enable the system-level kill switch for complete protection.
Protocol: In settings, confirm WireGuard is selected (or your provider's equivalent). If the app offers auto-select, use it.
Auto-connect: Enable 'auto-connect on startup' if you want the VPN active whenever Windows boots. This prevents the gap between login and manually starting the VPN.
Method 2: Windows built-in VPN client
Windows 11 has a built-in VPN client under Settings > Network and Internet > VPN. This supports IKEv2 and L2TP/IPsec but not WireGuard natively. It does not include a kill switch. We do not recommend this method for privacy use -- the provider's app is always the better option. Use the built-in client only if you need to connect to a corporate VPN that does not offer a custom app.
How to Set Up a VPN on iPhone (iOS 18)
Step 1: Download the app
Search for your VPN provider's app in the App Store. Use the exact name to avoid counterfeit apps. Download and install.
Step 2: Log in and connect
Open the app, log in, and tap Connect. The first time you connect, iOS will show a permission prompt: 'VPN would like to add VPN configurations to iPhone.' Tap Allow. This is required for the VPN to function. The VPN status appears in the iOS status bar as 'VPN' when active.
Step 3: Enable the kill switch on iOS
This step is critical and often missed. iOS does not expose an in-app kill switch the way Android does. To enable it:
- Go to iOS Settings > General > VPN and Device Management > VPN.
- Tap the (i) icon next to your VPN configuration.
- Enable 'Connect On Demand' and set it to 'Always On' (or configure domain rules if you want selective activation).
Without this, your real IP is exposed any time the VPN connection drops and reconnects -- for example, when switching between Wi-Fi and cellular. The always-on VPN profile prevents this.
Step 4: Verify
Open Safari with the VPN connected and visit ipleak.net. If your real IP appears, the VPN is not routing traffic correctly. Common causes: the VPN configuration was not added (check Settings > VPN), or the protocol is incompatible with your carrier's network (try switching to IKEv2 in the app settings).
Note on split tunneling: iOS does not support VPN split tunneling in the same way as Android and Windows. If split tunneling (routing only some apps through the VPN) is a requirement, ProtonVPN has an iOS implementation that supports it. Most other VPN providers, including NordVPN and Mullvad, do not support split tunneling on iOS due to platform restrictions.
How to Set Up a VPN on Android
- Go to the Google Play Store and search for your VPN provider's app. Download and install the official app.
- Open the app and log in.
- Tap Connect. Android will show a connection request: 'VPN wants to set up a VPN connection.' Tap OK.
- The key icon appears in the notification bar when the VPN is active.
Kill switch on Android: Unlike iOS, Android has a system-level always-on VPN with kill switch built into the OS. To enable it: Settings > Network and Internet > VPN > tap the gear icon next to your VPN > enable 'Always-on VPN' and 'Block connections without VPN.' This is more reliable than the in-app kill switch for most Android versions.
Split tunneling on Android: Android supports split tunneling natively, and most VPN providers expose it in their Android apps. In NordVPN for Android, find it under Settings > Split tunneling. You can exclude specific apps from the VPN tunnel (useful for banking apps that block VPN connections, local network access, or apps with geo-restrictions you do not want to bypass).
How to Set Up a VPN on macOS
- Download the macOS app from your VPN provider's official website (not the Mac App Store, where some providers have limited-feature versions).
- Open the downloaded .dmg file and drag the app to Applications.
- Open the app and log in. macOS will request permission to add a VPN configuration -- approve it.
- Select a server and connect.
Firewall and permissions: On macOS Sequoia (15.x), some VPN apps require additional system extension permissions under System Settings > Privacy and Security. If the VPN connects but traffic does not route correctly, check this section for blocked extensions.
Kill switch on macOS: macOS does not have a built-in kill switch equivalent to Android's always-on VPN. Rely on the VPN app's built-in kill switch. For NordVPN and Mullvad, this is in the app settings and works as expected. Disconnect behavior: if the VPN drops, all traffic stops until the VPN reconnects.
How to Set Up a VPN on Your Router
Router-level VPN setup routes all devices on your network through the VPN, including smart TVs, gaming consoles, and IoT devices that cannot run VPN apps. The tradeoff: all devices share the VPN connection, which adds latency to everything and may not suit gaming or video calls.
Which routers support VPN? ASUS routers (running AsusWRT), Netgear Nighthawk, and GL.iNet routers all support OpenVPN or WireGuard natively. Standard ISP-provided routers typically do not. DD-WRT and OpenWRT firmware can add VPN support to compatible routers.
Setup steps (ASUS router with NordVPN WireGuard, as an example):
- Log in to your router admin panel (usually 192.168.1.1).
- Go to VPN > VPN Client.
- Select WireGuard as the protocol.
- Download the WireGuard configuration file from your VPN provider's website (look for 'Manual config' or 'Router setup' in the account dashboard).
- Import the configuration file into the router's VPN client.
- Enable the VPN client and confirm devices are routing through it.
Router setup takes 15-30 minutes depending on your router model and familiarity with the admin interface. ExpressVPN has the most thorough router setup documentation of any provider we have tested, covering ASUS, TP-Link, Netgear, and GL.iNet with step-by-step screenshots.
How to Verify Your VPN Is Working
After setup on any device, run this 3-step check:
- IP check: Visit ipleak.net with the VPN connected. The IP shown should be your VPN server's IP, not your real IP. If your real IP appears in any section of the results, the VPN has a leak.
- DNS check: On the same ipleak.net page, check the 'DNS Addresses detected' section. Only your VPN provider's DNS servers should appear. If your ISP's DNS servers appear, you have a DNS leak.
- WebRTC check: Visit browserleaks.com/webrtc in your browser. If your real local IP or public IP appears, you have a WebRTC leak. Fix: install your VPN provider's browser extension (Chrome/Firefox), which suppresses WebRTC in the browser. Note that local network IPs (192.168.x.x) in WebRTC results are normal and expected.
For a detailed walkthrough of all four leak types and how to fix each one, see our complete VPN leak test guide.
Common Setup Problems and Fixes
| Problem | Likely cause | Fix |
|---|---|---|
| VPN connects but real IP still shows | Split tunnel misconfiguration or DNS leak | Disable split tunneling temporarily; run dnsleaktest.com extended test |
| VPN connects but internet does not work | Kill switch blocking traffic after VPN drop | Reconnect the VPN; check kill switch settings |
| iOS VPN disconnects when switching Wi-Fi to cellular | Always-on VPN profile not configured | Enable always-on VPN in iOS Settings > VPN |
| VPN cannot connect on hotel Wi-Fi | Captive portal blocking VPN before authentication | Disconnect VPN, authenticate on hotel portal, reconnect VPN; or switch to obfuscated servers |
| Streaming service blocks VPN | VPN IP range detected by streaming platform | Switch servers (US East, US West, etc.); some providers have dedicated streaming servers |
| macOS VPN extension blocked | System Extensions blocked in Security settings | Go to System Settings > Privacy and Security > allow the VPN extension |
Frequently Asked Questions
Do I need to set up a VPN on every device?
If you want VPN protection on a specific device, install the app on that device. The exception is router-level setup, which covers all devices on your home network without individual installation. Most VPN subscriptions allow 5-10 simultaneous device connections -- you can install on all your devices and connect from any of them within the limit.
Does setting up a VPN slow down my internet?
On a WireGuard-based VPN connected to a nearby server, the speed impact is typically 5-15% on a fast connection. On a gigabit fiber line, this is imperceptible. On a slow connection (under 50 Mbps), a VPN can occasionally cause buffering for 4K streaming if the server is far away. Connect to the server geographically closest to you for minimum overhead. See our speed test results for NordVPN and Mullvad for specific measurements.
Should I leave the VPN on all the time?
Yes, if it passes our leak test and does not significantly slow your connection. Turning a VPN on and off creates gaps in protection. The most dangerous moment is exactly when you forget to turn it back on -- connecting to a public Wi-Fi without a VPN because the habit was not fully formed. Most modern WireGuard-based VPNs on a paid plan are fast enough to run continuously without noticeable impact.
How do I know if my VPN is set up correctly?
Run the 3-step check in the verification section above: ipleak.net for IP and DNS, browserleaks.com for WebRTC. If all three show only VPN addresses (and the WebRTC local IP is a 192.168.x.x address rather than your real public IP), the setup is correct. Re-run this check after any app update or device OS update, since updates can occasionally reset VPN configuration settings.



