If Lvcha VPN cannot come up on an office network, debug the LAN policy before the node list. Finish the captive portal, clear PAC / manual proxy, switch the protocol to TCP, then decide whether the failure is “tunnel never starts” or “tunnel starts and the intranet dies.” Firewalls that drop UDP, transparent proxies that steal DNS, and MDM that blocks the Network Extension all look like a spinner. The home-broadband habit of hunting a 40 ms node does not apply.

Hotel splash pages are a different article: captive portal. Protocol A/B: UDP vs TCP. Permissions and packages: setup, download. Apple’s deployment note: VPN overview.

Tunnel never builds versus intranet dies after it does

Never builds: Connecting for minutes, auth errors, extension denied. Intranet dies: egress IP changed, but SharePoint, printers, and the booking panel time out. The first is the perimeter blocking a tunnel; the second is split tunnel sending RFC1918 to a pop. The fixes are opposites.

Control test: phone hotspot. Lvcha works on the hotspot, fails on the SSID → the wired/wireless policy. Fails on the hotspot too → account, build, or a second VPN on the PC. Disable the office PAC before you test the hotspot or you are still talking to the corporate proxy.

SignalLikelyMove
Connecting > 45 sUDP drop or extension blockedTCP; check MDM
Tunnel up, OA dead, news sites fineLAN in the tunnelDirect those prefixes
Tunnel up, public web dead, OA fineInspection / DNS hijackKill Switch off, watch certs
OS refuses to add a VPNPolicyIT ticket, stop reinstalling

PAC, audit proxies, TLS inspection

Windows Settings → Network → Proxy still pointing at an automatic script will ask that proxy before Lvcha. Corporate proxies often reject CONNECT from inside a tunnel, which looks like “Connected, no internet.” Turn the proxy off for the test; put it back only when IT requires it. Leftover AnyConnect / GlobalProtect / similar clients also sit on a local port—quit that process.

TLS inspection inserts a company root. Browsers may already trust it; the handshake to a Lvcha pop may not. That is not “turn on HTTPS decryption inside Lvcha.” On a managed PC, an unknown root is an IT question, not a cer you import from a forum. If 1.1.1.1/help throws a certificate warning, treat the device as inspected.

UDP, 802.1X, guest VLAN

Many office WLANs allow TCP 80/443 and silently drop UDP 443. UDP is fine at home; Connecting at work. Switch to TCP or the in-app “compatibility” label; if it comes up in 20 seconds, pin that SSID to TCP forever. No reinstall. See protocol guide.

802.1X not finished means you are still in a quarantine VLAN. The Wi-Fi icon lies. Kill Switch in that window also blocks the portal—disable it, authenticate, then bring the tunnel up. Guest versus staff VLANs differ; do not borrow a colleague’s 802.1X identity.

Office IPv6 plus an IPv4-only tunnel sends AAAA somewhere the inspect box likes better. Continue in IPv6. Internal AD DNS that black-holes public names is the corporate flavour of DNS leak; do not point the PC at 1.1.1.1 unless IT said you may.

Intranet stays Direct — and when to stop

Bypass the portal hostname, OA, the meeting stack, printer VLANs. If you only know “it is a 10-dot,” disconnect Lvcha for the meeting instead of guessing rules live. In per-app mode, pin the collaboration suite Direct and leave the browser you actually need in the tunnel list.

MDM that forbids VPNs is not a blog post you can out-clever. Mail IT the download page version string. Five node swaps on the same SSID with no tunnel: stop, use cellular for the one task that needs a tunnel, leave office traffic Direct. More: FAQ, guides.

This page is a failure-mode map (portal, proxy, protocol, split). It is not a guide to evading monitoring you are subject to on a machine you do not own.