Restart the router and device
Save work, restart the phone or computer, then power the router off for 30 seconds and let it fully reconnect. On full fibre, photograph unusual ONT lights before restarting anything.
Wi-Fi can stay connected even when internet access fails. Start with four fast checks, then use Windows, Mac, iPhone, Android, Chromebook or Smart TV steps to isolate DHCP, DNS, gateway, router or ISP faults.
Connected but not online
Use four fast checks first, then compare the device, router gateway, DHCP, DNS, Ethernet and provider path to find the first point where internet access fails.
Quick fix checklist
These are the safest high-yield checks before deeper DNS, DHCP or adapter changes. Do not factory-reset the router.
Save work, restart the phone or computer, then power the router off for 30 seconds and let it fully reconnect. On full fibre, photograph unusual ONT lights before restarting anything.
Turn Airplane Mode on for 10 seconds, then turn it off. This forces the device to rebuild its Wi-Fi connection without changing saved settings.
Forget the saved network, reconnect and enter the password again. This clears a stale Wi-Fi profile, cached security state or bad lease association.
Use mobile data to check your ISP (Internet Service Provider) outage or status page. If every home device is offline, the fault may be outside your Wi-Fi network.
Start here
Do not reset everything at once. Start by proving the scope, then check whether the device can reach the router and whether the router can reach the internet.
The broadband service is probably available. Focus on the affected device, saved network profile, DHCP lease, DNS, VPN or clock.
The router, ONT, WAN cable, provider session or external service is the first suspect rather than one device.
The local Wi-Fi path is working. Check the router’s internet status, DNS, captive portal, VPN or provider service.
Interactive check
Select the state that best matches the connection now. The result gives you the next diagnostic section rather than claiming a final cause from one clue.
Quick reference
Symptoms, likely cause and first diagnostic step are combined here so you can move directly from the message on screen to useful evidence.
A stale saved network, DHCP lease, DNS cache, VPN, Private Relay, security software or incorrect device time is more likely than a broadband outage.
Next: forget and rejoin Wi-Fi, then compare the same device with another network.The router can still broadcast Wi-Fi after losing its broadband session. A WAN cable, ONT, router authentication or provider fault is more likely.
Next: check router and ONT service lights, test Ethernet, then use the broadband-down guide. Run the ping test only when some external traffic returns.The core connection is carrying traffic, so the fault is more likely at the DNS, browser, filtering or certificate layer.
Next: use the websites-not-loading diagnostics guide rather than repeating the browser-layer checks here.The device has created an APIPA fallback because it did not receive a usable DHCP address from the router.
Next: renew the lease, forget the network and check whether other devices also fail to obtain an address.A captive portal may be blocked by VPN, Private Relay, custom DNS or HTTPS-only behaviour.
Next: temporarily disable those services and open a plain HTTP page to trigger the login screen. If the fault consistently follows the VPN, use the VPN troubleshooting checklist.The Wi-Fi radio may be healthy while the optical handoff or Ethernet link to the router has failed.
Next: record LOS, PON and LAN/PORT lights before restarting anything.Test in order
Keep the same device and change one variable at a time. The first failed comparison tells you which section to use.
If the second device works, keep the investigation on the original device. If both fail, continue towards the router and broadband path.
Apps working while websites fail points towards DNS, browser, filtering or certificate problems rather than a total outage.
Try the router admin address shown by your device, commonly 192.168.1.1 or 192.168.1.254. If it opens, the local Wi-Fi link is working.
A 169.254.x.x address indicates APIPA. Also set date, time and time zone to update automatically so secure certificate checks can succeed.
On guest Wi-Fi, temporarily disable VPN, custom DNS or Private Relay and open a plain HTTP page. On home Wi-Fi, compare with those services paused.
Ethernet working isolates the problem to Wi-Fi or the device. Ethernet failing across devices moves the fault to the router, ONT, WAN cable or provider.
Use mobile data to check the provider status page. Record device scope, light colours, gateway access and Ethernet results before support changes anything.
Diagnostic next step
Message reference
Use the wording on screen as a clue, not a final diagnosis. Confirm it with another device and the router or Ethernet checks.
| Device or context | Typical message | Likely bottleneck | Best next action |
|---|---|---|---|
| Windows 10 or 11 | No Internet, Secured | Stale DNS or DHCP state, VPN/security conflict, or router broadband loss. | Forget and reconnect to Wi-Fi; if needed, run ipconfig /flushdns and ipconfig /renew. |
| iPhone, iPad or Mac | No Internet Connection | Private Wi-Fi Address, Private Relay, VPN, stale lease or captive portal loop. | Renew the lease, compare with VPN or Private Relay paused, and test another device. |
| Android or smart TV | Connected, cannot provide internet | Clock mismatch, saved-network corruption, DNS failure, weak Wi-Fi or router WAN loss. | Set time automatically, forget and rejoin the network, then compare another device in the same room. |
| Public or guest Wi-Fi | Redirect or login never appears | Captive portal blocked by VPN, custom DNS, Private Relay or HTTPS-only behaviour. | Open a plain HTTP page in a clean browser tab to trigger the portal. |
| Full-fibre home line | All devices connected but offline | ONT optical sync, WAN cable or router authentication fault. | Record ONT LOS, PON and LAN/PORT lights before restarting the router. |
APIPA clue: an address beginning 169.254 means the device has not obtained a normal DHCP address from the router.
Device-specific fixes
Use the section for the affected device only. Menu labels can vary slightly by operating-system release or Android manufacturer.
ipconfig. If the IPv4 address begins 169.254, DHCP has failed. If Windows reports Default Gateway Unavailable, check the gateway and adapter state.ipconfig /release, ipconfig /renew and ipconfig /flushdns.Why this helps: Windows can show Wi-Fi as connected while a stale DHCP lease, DNS cache, adapter state or missing default gateway prevents internet routing.
Why this helps: renewing DHCP and separating saved-location, DNS and private-address settings distinguishes a Mac configuration fault from the router or ISP.
Why this helps: iOS can remain associated with the access point while a saved profile, captive portal, VPN/Private Relay path or network configuration blocks internet traffic.
Why this helps: Android can report a healthy Wi-Fi association even when DHCP, a static-IP conflict, custom DNS, captive-portal state or the upstream router path is broken.
Why this helps: ChromeOS Diagnostics can separate local Wi-Fi, IP configuration, DNS and Google-service connectivity without immediately resetting the whole home network.
Why this helps: the hotspot comparison separates a streaming-device problem from a home Wi-Fi or broadband fault without changing router-wide settings.
Menu paths reviewed against current Microsoft Support, Apple Wi-Fi settings, Apple iPhone/iPad troubleshooting, Android Help and ChromeOS Diagnostics.
↑ Back to guide indexCopy-paste command helper
Choose the operating system and the check you want to run. These commands inspect or refresh the device network state; they do not change router settings. Windows release/renew briefly interrupts the device connection.
ipconfig /allUK hardware check
If the whole home is offline, hardware lights can move the diagnosis away from the phone or laptop. Openreach ONT labels are fairly consistent, but router and Virgin Media Hub colours vary by model, so use the router result as triage rather than a definitive fault code.
Use this only if your fibre box actually has PON/LOS labels. Some Openreach ONTs use different labels such as Optical.
Router colour meanings differ between BT, Sky, TalkTalk, Virgin Media and individual Hub generations. Select the closest general state, then use the provider's own light guide if needed.
For model-specific meanings, use your provider's help page rather than assuming that the same colour means the same thing on every router.
The checker will suggest the next fault boundary without claiming a cable break or provider fault from one light alone.
Openreach ONT guidance cross-checked against BT's Openreach modem light guide. A solid green PON with LOS off normally means the fibre link is recognised; persistent red/flashing LOS or abnormal PON states need optical/service checks.
↑ Back to guide indexAdvanced checks
These details preserve the technical depth without interrupting the main fault-boundary workflow.
A 169.254.x.x address is a self-assigned APIPA fallback. Forget and rejoin Wi-Fi, renew the lease and check whether the router’s DHCP service is issuing normal local addresses to other devices.
If the device was configured manually, set it to Obtain an IP address automatically (DHCP) unless the network administrator supplied a static address. Two devices using the same manual address can create an IP address conflict.
If apps or direct IP connections work but websites fail by name, the connection may be online while the DNS server is not responding. Remove an incorrect manual DNS entry, flush the local DNS cache where supported and retest more than one domain.
Continue with the websites-not-loading diagnostics guide for deeper DNS, browser and HTTPS checks.
The default gateway is normally the router address your device uses to leave the local network. If Windows reports Default Gateway Unavailable, or the gateway field is blank or unreachable, renew DHCP, re-enable the adapter and confirm the router gateway opens locally.
If several devices cannot reach the gateway, investigate the router rather than changing DNS.
Guest networks can block all traffic until a splash page is accepted. VPNs, custom DNS and Private Relay can prevent the redirect.
Open a plain HTTP page in a clean tab and re-enable privacy services after the portal has completed.
A badly wrong clock can invalidate HTTPS certificates and app authentication while the Wi-Fi connection itself remains active.
Set date, time and time zone to automatic, then close and reopen the affected browser or app.
A router may continue broadcasting Wi-Fi when the ONT has lost optical sync. Record LOS, PON and LAN/PORT lights and check the Ethernet lead from the ONT to the router WAN port.
Do not bend, pull or look into the end of a fibre lead. If LOS remains red or flashing, contact the broadband provider.
Apply the result
Apply one route only after the tests identify the failed layer.
Do: forget and rejoin Wi-Fi, restart the device, update its network driver or software and compare VPN or privacy services.
Retest: the same website and app on the same Wi-Fi.Do: renew the lease, remove manual addressing conflicts and restart the router once if several devices are affected.
Retest: confirm the device receives a normal private address from the router.Do: move to the websites-not-loading diagnostics guide for DNS, browser, filtering and certificate checks.
Retest: more than one domain in a clean browser session.Do: pause VPN, custom DNS or Private Relay and open a plain HTTP page to trigger the portal.
Retest: sign in, then restore privacy services.Do: use the unstable Wi-Fi guide for signal, channel, mesh and device checks.
Retest: the same device over Ethernet and Wi-Fi.Do: check cables, router and ONT lights, provider status and the broadband-down guide.
Retest: after one controlled restart or provider line test.Escalate with evidence
Escalate only after the scope and first failed layer are clear.
Every device and Ethernet fail, router or ONT service lights are abnormal, the provider status page reports an ISP (Internet Service Provider) outage, or the router cannot establish its internet session.
Only one managed device fails, the issue follows a VPN or security profile, or the device cannot obtain a valid address while other devices work.
UK outage check: If every device is offline on BT, Virgin Media, Sky or TalkTalk, use mobile data to check the provider's own status service before resetting DNS or Wi-Fi settings. A Virgin Media Hub can keep broadcasting Wi-Fi even when the upstream broadband service is unavailable.
Focused answers
These answers match the FAQ structured data in the page head.
The device has joined the local Wi-Fi network but cannot reach the wider internet. Common causes include router broadband loss, DHCP or APIPA address faults, DNS failures, VPN or Private Relay loops, captive portal blocks, device clock errors and provider outages.
Start by checking whether the fault affects one device or every device. Then try a website and an app, open the router gateway, check the device IP address and compare Wi-Fi with Ethernet.
An APIPA address usually starts with 169.254.x.x. It appears when a device cannot get a normal local IP address from the router's DHCP server, so it may show Wi-Fi connected while being unable to route traffic to the internet.
Forget and reconnect to the Wi-Fi network, restart the device, flush DNS, renew the IP lease, check for VPN or security software conflicts and confirm whether other devices can use the same router.
That pattern points towards DNS, browser cache, HTTPS inspection, Private Relay, VPN, content filtering or browser profile problems rather than a complete broadband outage.
It means the device may still have a working Wi-Fi and internet path but cannot translate website names into IP addresses. Check manual DNS settings, flush the DNS cache where supported and compare more than one website or app.
The device cannot reliably reach the router address used to send traffic outside the local network. Renew DHCP, re-enable the network adapter and confirm that the router gateway opens before changing DNS.
On Openreach ONTs that use PON and LOS labels, a solid green PON light with LOS off normally means the fibre link is recognised. PON flashing with LOS off can mean the ONT is verifying the connection. A red or flashing LOS light, PON off, or persistent abnormal combinations point towards the optical link or service and should be checked with the broadband provider.
A Virgin Media Hub can continue broadcasting Wi-Fi even when its upstream broadband connection is unavailable. Check another device, compare Ethernet, review the Hub status light for your model and use Virgin Media’s service-status checker before changing device DNS or Wi-Fi settings.
Contact the provider if every device fails, Ethernet also has no internet, router or ONT service lights show a line fault, or provider status checks confirm an outage outside the home network.