Do VPNs Work on Airport and Hotel Wi-Fi?
A practical look at how VPN airport Wi-Fi connections actually behave once a captive portal is involved, what a VPN protects on these networks, and the one step order that trips up most travelers.
Quick answer
Yes, a VPN works on airport and hotel Wi-Fi, and in most cases it works exactly the same way it does on any other network. The one real complication is the login page ("captive portal") that airport and hotel networks almost always show you first — you generally have to complete that login with the VPN off, then turn the VPN on afterward, because the portal needs to see your unencrypted traffic to let you online at all. Once you are past that screen and the VPN connects, it encrypts your traffic the same way it would at home, which is exactly the protection you want on a shared, semi-public network where you do not control the router, the other devices connected to it, or who administers it. A small number of heavily locked-down networks add extra firewall rules that block some VPN connections outright, but a modern VPN app with more than one protocol option can usually work around that.
What Makes Airport and Hotel Wi-Fi Different From Wi-Fi at Home?
At home, you control the router, you know who else is on the network, and you (hopefully) set a real password on it. None of that is true on airport or hotel Wi-Fi. These are shared networks used by hundreds or thousands of strangers a day, administered by IT staff you will never meet, running on hardware you cannot inspect, often left unpatched for long stretches because updating live production Wi-Fi at a busy airport terminal is operationally disruptive. That combination — many mutually distrusting users, third-party administration, and infrastructure that is not always kept current — is exactly the environment where the handful of well-known local-network attacks actually work.
Two specifics are worth understanding because they explain most of what people actually mean when they ask whether a VPN "works" on these networks. First, most airport and hotel networks are technically open (no Wi-Fi password at all) or use a single shared password printed on a card at check-in or displayed on an airport signage board — either way, everyone on the network is using the same credential, or no credential, which is a much weaker starting point than a private home network with its own unique password. Second, almost all of them sit behind a captive portal: a login or "accept terms" web page you are forced to see before the network lets your traffic reach the open internet. That second detail is the part that actually determines how a VPN behaves on these networks, more than anything about the Wi-Fi signal itself.
Neither of these things makes airport or hotel Wi-Fi uniquely dangerous compared to, say, a coffee shop's open network — the underlying risk profile is the same category of public, shared Wi-Fi covered in more general terms in our public Wi-Fi guide. What is specific to airports and hotels is the captive portal step, and that is worth walking through in detail because it is the actual source of most "my VPN isn't working" confusion travelers run into.
Does a VPN Work on Airport Wi-Fi?
Yes. A VPN airport Wi-Fi connection works the same way a VPN works on any Wi-Fi network, technically speaking — it opens an encrypted tunnel between your device and a VPN server, and everything you send and receive travels through that tunnel instead of being visible in plain form to the local network. The part that catches people off guard is not whether it works, but when it can start working: the captive portal has to let your device online first, and it usually can't do that if your traffic is already encrypted and routed somewhere else.
Here is what actually happens step by step on a typical airport network. You join the Wi-Fi network by name, exactly as you would anywhere else. Your device gets an IP address from the airport's router, but at this stage you are in what is sometimes called a "walled garden" — the network intercepts your first web request and redirects you to a login or terms-acceptance page, regardless of what site you actually tried to visit. You accept the terms, sometimes enter an email address or a boarding pass number, and only then does the router's firewall open up and let your traffic reach the real internet. If your VPN app is already trying to connect at this point, it usually can't, because the captive portal is intercepting exactly the same kind of traffic the VPN needs to establish its tunnel. Once you are through the portal and have normal (unencrypted, at this point) internet access, turning the VPN on works exactly like it would at home: your traffic gets encrypted, routed to the VPN server, and from there out to the wider internet.
So the honest answer to "does a VPN work on airport Wi-Fi" has two parts. Yes, it works, and once connected it protects your traffic the same way it always does. But it typically cannot connect until after you clear the captive portal, which means there is a short window — usually well under a minute — where your device is on the airport network without VPN protection while you are just accepting terms and getting online. That window is a normal, expected part of how these networks are designed, not a sign that anything is wrong with your VPN app.
Does a VPN Work on Hotel Wi-Fi?
The mechanics are essentially identical to airport Wi-Fi, with one extra wrinkle: hotel networks vary far more in quality than airport networks do. A large international hotel chain's Wi-Fi is often run by a dedicated managed-network vendor with reasonably current equipment. A small independent hotel or guesthouse might be running consumer-grade routers that haven't been reconfigured in years, sometimes with the same Wi-Fi password handed out to every guest for the network's entire operational life. Both setups will show you a captive portal — often asking for your last name and room number instead of a boarding pass, since the hotel wants to tie your session to a guest folio for billing purposes — and both work the same way once you're past it: join the network, clear the portal, then turn the VPN on.
Hotel Wi-Fi has one more relevant history worth mentioning honestly: hotel networks have specifically been used as an attack vector before, not hypothetically. Security researchers at Kaspersky Lab documented a real campaign, publicly reported in 2014 and nicknamed "DarkHotel," in which attackers compromised hotel Wi-Fi infrastructure to target specific business travelers with malware disguised as legitimate software update prompts after they connected. That is a genuinely documented case, not a scare story, and it illustrates the underlying point well: hotel networks are administered by a third party you have no visibility into, on hardware you cannot verify, and that is exactly the situation a VPN's encryption is designed to reduce the blast radius of — though, as covered further down, a VPN would not have stopped that specific attack on its own, since it relied on tricking a person into running a malicious file rather than intercepting VPN-protected traffic directly.
Practically, this means the advice for hotel Wi-Fi is the same as for airport Wi-Fi, just with a bit more reason to actually follow it: clear the portal, connect the VPN promptly afterward, and treat any pop-up prompting you to install "required" software to access the hotel network as an immediate red flag rather than something to click through.
Why Won't My VPN Connect Right Away? (The Captive Portal Problem)
This is the single most common source of confusion, so it is worth explaining exactly what is happening under the hood. A captive portal works by intercepting your device's early DNS and HTTP requests and redirecting them to its own login page, no matter what site you actually asked for. Your operating system (iOS, Android, Windows, and macOS all do this slightly differently) typically detects this redirect automatically and pops up a login window for you.
A VPN, by design, tries to route all of your device's traffic — including that early detection traffic — through an encrypted tunnel to a VPN server. If the VPN successfully grabs your traffic before you've cleared the portal, the captive portal never gets the chance to intercept and redirect it, your device never sees the login page, and you end up stuck with a VPN that appears to connect but produces no actual internet access, because the airport or hotel's firewall is still blocking your device's wider internet access until you complete that login step. This is the actual mechanism behind the extremely common traveler complaint of "my VPN connects but nothing loads" on these networks — it's not usually a broken VPN, it's an un-cleared captive portal underneath it.
The fix is simple and consistent across providers: turn the VPN off (or don't start it yet), join the Wi-Fi network, let the captive portal page load, complete whatever login or terms-acceptance step it asks for, confirm you actually have internet access (try loading any ordinary website), and only then open your VPN app and connect. Most VPN apps, including all four covered on this site, do not auto-connect the instant you join a new Wi-Fi network unless you've specifically turned on an auto-connect-for-untrusted-networks feature — if you have that feature enabled, it is worth disabling it for travel, or at least being aware it might be the reason your portal page never loads.
What a VPN Actually Protects You From on These Networks
Once connected, a VPN's protection on airport or hotel Wi-Fi is the same as anywhere else, and it is worth being specific about what that protection actually covers rather than treating "a VPN protects you" as a vague blanket statement.
Local network eavesdropping. On a shared network with strangers, someone running packet-capture software on the same Wi-Fi can, in principle, see the traffic of other devices on that network — this is a long-documented weakness of open or shared-password Wi-Fi, not a hypothetical. A VPN's encryption means that even if someone is capturing your traffic on the local network, what they see is scrambled, encrypted data going to a single VPN server, not the actual sites you're visiting or the content of what you send.
Evil twin and rogue access point risk. Airports and hotels are common settings for a specific trick: an attacker sets up their own Wi-Fi hotspot with a name deliberately similar to the real one ("Airport_Free_WiFi" instead of "Airport-WiFi," for example), hoping travelers connect to the fake network by mistake. If you do connect to a rogue network like that, a VPN still meaningfully limits the damage, because your traffic is encrypted before it reaches whoever is running that rogue hotspot — they can see that you're using a VPN and roughly how much data you're sending, but not the content or destination of your actual browsing.
Hiding your browsing from the network operator. Whoever administers the airport or hotel network technically has the ability to log which sites devices on their network connect to, at least at the domain level, unless every connection is separately encrypted. A VPN routes that visibility away from the local network operator and toward the VPN provider instead — which is a meaningful shift if you trust your VPN provider's no-logs claims more than you trust an unknown airport or hotel IT contractor's data-handling practices, though it is worth being clear-eyed that this shifts trust rather than eliminating it entirely.
Geo-restricted access while traveling. A secondary, non-security benefit: connecting to a VPN server back in your home country lets you reach accounts, banking sites, or streaming services that sometimes behave differently or restrict access when they detect an unfamiliar foreign IP address, which is a common practical reason travelers use a VPN on these networks even before considering the security angle.
What a VPN Does Not Protect You From
Just as important, and consistently underplayed by VPN marketing generally: a VPN is not a complete travel-security solution, and treating it like one leaves real gaps uncovered.
The captive portal window itself. As covered above, there is a short period before you clear the portal where your device is on the network unencrypted. In practice this window rarely involves anything sensitive — you're typically just loading a login page and clicking "accept" — but it is a genuine gap, not a hypothetical one, and it is worth not doing anything sensitive (like logging into a banking app) during those first few seconds on a new network.
Phishing and social engineering. A VPN encrypts your connection and can mask your IP address; it does nothing to stop you from typing your real password into a convincing fake login page, or from being tricked into installing malicious software disguised as a required network driver or update — exactly the technique used in the real hotel Wi-Fi attack referenced earlier. Any pop-up on airport or hotel Wi-Fi that asks you to install something before you can get online should be treated with real suspicion; legitimate captive portals ask you to view a web page and agree to terms, they do not need you to install an executable.
Malware already on your device. If your laptop or phone already has malware on it — from a prior download, a malicious browser extension, or any other source — a VPN encrypting your network traffic does not remove that malware or stop it from doing whatever it was designed to do locally on your device. See our related breakdown of what a VPN does and doesn't protect against for the broader picture beyond travel networks specifically.
Physical device security. A VPN has nothing to do with someone physically stealing your unlocked laptop from an airport seat while you step away, or shoulder-surfing your screen in a crowded gate area. Ordinary device hygiene — screen locks, not leaving devices unattended, privacy screens in crowded public seating — remains just as important with a VPN running as without one.
Perfect anonymity from your VPN provider. A VPN shifts visibility of your browsing away from the local network operator and toward your VPN provider instead, as noted above. It does not make your activity invisible to everyone, everywhere, in every circumstance — it changes who is in a position to see it, which is a real and useful shift, but not the same as true anonymity.
Do Airports or Hotels Ever Block VPNs Outright?
Occasionally, yes, though outright blocking is the exception rather than the norm on most airport and hotel networks in most countries. When it happens, it is usually a side effect of a general corporate or institutional firewall policy rather than a deliberate decision to specifically target travelers using a VPN — the same firewall appliance that blocks certain ports or filters certain protocols for security reasons can end up catching VPN traffic as collateral, especially older or more heavily locked-down protocols like standard OpenVPN over its default UDP port.
A separate, more serious version of this exists at the country level rather than the network level: some countries restrict or heavily monitor VPN use nationally, meaning the blocking (where it exists) applies everywhere within that country's networks, airport and hotel Wi-Fi included, as a matter of national policy rather than a specific airport or hotel's own choice. That is a materially different situation from an individual property's firewall configuration, and it is worth checking the legal and practical status of VPN use for your specific destination country ahead of time — our guide to where VPN use is legal covers that ground in more detail, since it varies meaningfully by country and is worth knowing before you rely on a VPN as your primary security tool while traveling somewhere unfamiliar.
Where a network-level block or restrictive firewall is the more likely explanation — a business-center kiosk, a conference-venue network, or a hotel with an unusually aggressive IT policy — a VPN app that offers more than one connection protocol has real practical value. Protocols like OpenVPN configured over TCP port 443 (the same port ordinary encrypted web traffic uses) or a dedicated obfuscation/stealth mode, where available, are specifically designed to be harder for a basic firewall to distinguish from regular encrypted web browsing, and switching to one of those is the standard troubleshooting step when a default connection attempt is refused on a restrictive network.
How to Actually Connect a VPN on Airport or Hotel Wi-Fi (Step by Step)
Putting everything above into a simple, repeatable sequence:
- Join the Wi-Fi network by name, the same way you would on any network, with your VPN app closed or set to not auto-connect.
- Let the captive portal load. If it doesn't appear automatically, open a browser and try loading any ordinary website — most devices and portals will redirect you to the login page at that point.
- Complete the portal's login or terms-acceptance step (email address, room number and last name, "accept terms" button, or similar, depending on the property). Decline any prompt to install software, a "network optimizer," or a browser extension — a real captive portal never requires that.
- Confirm you actually have internet access by loading a normal website before doing anything else, just to make sure the portal step genuinely completed.
- Open your VPN app and connect, choosing a server and protocol as you normally would. Give it a few extra seconds on unfamiliar networks — some captive portals impose a brief additional delay before releasing full traffic to new devices.
- Verify the VPN is actually active — most apps show a clear connected state, often with the server location and, in some apps, your new apparent IP address — before doing anything sensitive like logging into email, banking, or work accounts.
- If the VPN won't connect at all, try switching protocols within the app (WireGuard to OpenVPN TCP, or to a dedicated obfuscation mode if the app offers one) before assuming the network has blocked VPN traffic entirely — a protocol switch resolves the large majority of connection failures on restrictive networks.
One more habit worth building specifically for airport and hotel networks: enable your VPN app's kill switch if it has one (all four providers covered on this site include this feature). A kill switch blocks all internet traffic if the VPN connection drops unexpectedly, rather than silently falling back to your unencrypted connection — which matters more on unfamiliar public networks, where a dropped VPN connection could otherwise leave you exposed without any visible warning.
What to Look for in a VPN Specifically for Travel
Not every feature that matters for a VPN in general carries equal weight while traveling through airports and hotels specifically. A few things are worth prioritizing:
Multiple protocol options. Given how often restrictive network firewalls are the actual obstacle, an app that offers more than just one protocol — ideally a fast modern option like WireGuard for normal use, plus a fallback like OpenVPN over TCP 443 or a dedicated obfuscation mode for locked-down networks — gives you a real troubleshooting path instead of a dead end when the default connection method is blocked.
A working kill switch. Already covered above, but worth repeating: this is one of the more consequential features specifically for public, unfamiliar networks, where a silent VPN drop is easy to miss.
Reliable mobile apps. Most airport and hotel VPN use happens on a phone or laptop rather than a desktop at home, so an app that is actively maintained on iOS and Android, and reconnects cleanly after network changes (like switching from airport Wi-Fi to cellular data as you walk toward your gate), matters more while traveling than it typically does at home.
Enough simultaneous device connections. Travel often means multiple devices — phone, laptop, sometimes a tablet — all needing protection on the same trip, which makes a generous simultaneous-connection allowance more practically relevant than it might be for a single-device home user.
Installing before you travel, not after. A small but easy-to-miss detail: download and set up your VPN app, and confirm it actually connects, before you leave for the airport rather than after you arrive somewhere with unfamiliar Wi-Fi and possibly restricted app-store access. Some countries restrict access to VPN provider websites or app store listings specifically, which makes "I'll just download it when I get there" a real risk in a way it usually isn't for everyday domestic use.
Among the four providers covered on this site, NordVPN is generally positioned around a large global server network and broad platform support, useful for finding a nearby, uncongested server in a wide range of destination countries; Proton VPN leans on a privacy-first reputation and offers a genuinely usable free tier, which is a reasonable starting point if you want to test a captive-portal workflow before committing to a paid plan for an upcoming trip; PureVPN is generally positioned around a generous simultaneous-device allowance, useful for travelers covering a phone, laptop, and tablet on one plan; and FastestVPN is generally positioned as a lower-cost, entry-level option with broad platform support for travelers who want the basics covered. All four include a kill switch and support more than one connection protocol. None of this is a claim about current pricing or star ratings — those fields are intentionally left unfilled on this site until independently verified, so check each provider's own site for current plans before choosing.
What About a Work VPN Instead of (or Alongside) a Personal One?
Business travelers often run into a specific wrinkle: a company-issued laptop already has a corporate VPN installed, used to reach internal systems, and the natural question is whether that already covers the airport or hotel Wi-Fi risk, or whether a personal VPN is still worth adding on top.
A corporate VPN is usually built for a different purpose than the consumer VPNs covered on this site: it typically exists to give you secure access into your employer's internal network and resources, not primarily to protect your general browsing on public Wi-Fi, though the two overlap in practice because a corporate VPN also encrypts your traffic in transit. Many corporate VPN setups use split tunneling, meaning only traffic destined for company systems actually routes through the corporate tunnel, while ordinary browsing (checking personal email, reading the news, using a maps app) goes out over the local network directly, unencrypted at the network level, exactly as it would with no VPN at all. Whether that's the case for your specific employer's setup depends entirely on how their IT department configured it — some route all traffic through the corporate tunnel by default (full tunneling), others don't, and it is worth actually asking your IT team which model your company uses rather than assuming.
The same captive-portal sequencing described throughout this article applies regardless of which VPN you're using: join the network, clear the portal, then connect whichever VPN you're using. If your corporate VPN is full-tunnel and you can confirm it's actually running and covering all your traffic, that alone addresses the local-network eavesdropping risk this article is mainly about, for the device it's installed on. If it's split-tunnel, or if you're not certain which model your employer uses, running a personal VPN as well (or checking with IT about their own policy on doing so, since some employers have specific rules here) is a reasonable way to close that gap for your non-work browsing on the same device.
Common Myths About VPNs on Airport and Hotel Wi-Fi
A few claims about VPNs on these specific networks circulate often enough to be worth addressing directly.
"Airports and hotels can see everything I do once I'm on their Wi-Fi, VPN or not." Not accurate once a VPN is actually connected and the captive portal has been cleared. A properly connected VPN encrypts your traffic before it leaves your device, meaning the network operator sees encrypted data flowing to a VPN server, not the actual sites or apps you're using. This myth usually comes from conflating the brief, unencrypted pre-portal window (real, but short and generally low-stakes) with your entire session on the network (not accurate once the VPN is active).
"A VPN makes me completely anonymous on public Wi-Fi." Also not accurate, and covered in more detail earlier in this article — a VPN shifts who can see your traffic (away from the local network operator, toward your VPN provider) rather than making it invisible to literally everyone. It is a meaningful and genuinely useful shift, not a claim of total anonymity.
"Free airport Wi-Fi is always more dangerous than paid hotel Wi-Fi." Price is not a reliable signal of network security either way. A free airport network run by a professional, well-resourced operator can be better maintained than a paid hotel network run on aging equipment by a small, independent property, or the reverse. The underlying risk factors that actually matter — how the network is administered, how current its equipment is, and whether it's realistically a target for the kind of attack described earlier in this article — don't track cleanly with whether you're asked to pay for access.
"If my VPN app shows 'Connected,' I'm definitely fully protected." Usually true, but worth a moment's verification rather than blind trust, especially right after joining an unfamiliar network. A kill switch (covered earlier) is exactly the safeguard for the edge case where a connection silently drops and reconnects without full protection in between — turning it on removes the need to manually double-check every time.
"VPNs are illegal or restricted at every airport." Not accurate as a blanket statement — VPN legality is a matter of national law and varies by country, not something airports or hotels individually decide, and in the large majority of countries VPN use is entirely legal for ordinary personal use. Our guide to where VPN use is legal covers the actual country-by-country picture.
Should You Even Use Airport or Hotel Wi-Fi, VPN or Not?
A VPN is a strong mitigation, not a reason to stop thinking about the network you're on entirely. A few habits are worth pairing with it, whether or not a VPN is running:
Confirm the network name before joining. Ask staff for the exact official network name rather than guessing from a list of similarly-named options, given how common the "evil twin" naming trick described earlier actually is in these specific settings.
Keep your device and apps updated. Security patches close known vulnerabilities that could otherwise be exploited by anyone else on a shared network, VPN or not.
Avoid installing anything a network prompts you to install. Covered above, but it bears repeating because it is the single most common way real attacks on hotel and airport-style networks have actually succeeded, more so than any weakness in encryption itself.
Consider your phone's cellular data or a personal hotspot for the most sensitive tasks, such as a one-time banking transfer or entering payment details somewhere new, if you have signal and a reasonable data allowance. This isn't always practical, especially in-flight or abroad with limited roaming data, but it sidesteps the shared-network risk category entirely for the handful of moments where it matters most, rather than relying on any one layer of protection alone.
Use HTTPS sites and be alert to certificate warnings. Most of the modern web is encrypted site-to-site by default now, which is a separate, complementary layer of protection to what a VPN provides at the network level — and a browser warning about an invalid or unexpected certificate on a public network is worth taking seriously rather than clicking past, regardless of whether a VPN is active.
None of this replaces a VPN for the specific risks it addresses — local network eavesdropping and rogue-hotspot interception chief among them — but a VPN is one solid layer in a small stack of reasonable habits, not a single substitute for all of them. Combined, they cover most of the realistic risk that airport and hotel Wi-Fi actually presents to an ordinary traveler.
Can I use a VPN on airport Wi-Fi?
Yes. VPN airport Wi-Fi connections work the same way a VPN works on any network — the only real complication is that most airport networks show a captive portal login page first, and the VPN generally needs to be off until you clear that page, then turned on afterward for full protection.
Why does my VPN not connect on hotel or airport Wi-Fi?
The most common cause by far is trying to connect the VPN before completing the network's captive portal login. The portal needs to see your unencrypted traffic to let you online, and a VPN that grabs your traffic first can block that from happening. Join the network, complete the login page, confirm you have normal internet access, then connect the VPN.
Do airports or hotels block VPNs?
Outright blocking is uncommon on most airport and hotel networks, though some heavily locked-down business or conference networks apply firewall rules that catch certain VPN protocols as a side effect of general security policy. A VPN app that offers more than one protocol, such as OpenVPN over TCP 443 or a dedicated obfuscation mode, can usually work around this. Separately, some countries restrict VPN use nationally, which is a different and more serious situation worth checking ahead of travel.
Is it safe to enter my room number and name on a hotel Wi-Fi login page without a VPN on?
Generally yes for that specific, brief step — a captive portal login page is typically just confirming your stay for billing purposes, and a VPN usually cannot be active during that step anyway since the portal needs to see the request. The bigger risk on hotel Wi-Fi comes afterward, from browsing unprotected on a shared network or from being tricked into installing something the portal did not actually require, which is why turning the VPN on promptly once you're through the login matters more than the login step itself.
Does a VPN slow down airport or hotel Wi-Fi a lot?
A VPN adds some overhead from encryption and routing on any network, airport and hotel Wi-Fi included, and these networks are often already congested with many simultaneous users, which can compound the effect. Choosing a nearby VPN server and a modern protocol like WireGuard typically keeps the difference modest for everyday browsing. Our full breakdown of <a href="/en/articles/does-a-vpn-slow-down-internet/">how much a VPN slows down your internet</a> covers the underlying factors in more detail.
Should I turn my VPN on before or after joining airport Wi-Fi?
After joining the network and after completing the captive portal login page, not before. Trying to connect the VPN first commonly prevents the portal from loading at all, which is the single most common reason travelers report their VPN "not working" on these networks.