# Connecting

Open the app and press the power button. That is the whole thing.

If you have more than one vploq, pick the one you want first. On desktop the
current device is a dropdown in the top bar; on a phone, tap **Change device**.
The name above the button is the one you are connecting to.

## What the statuses mean

<Mermaid chart={`stateDiagram-v2
  [*] --> Disconnected
  Disconnected --> Connecting: press connect
  Connecting --> Connected: tunnel up
  Connected --> Disconnecting: press disconnect
  Disconnecting --> Disconnected
  Connecting --> Error: could not connect
  Error --> Disconnected
`} />

| Status | What is happening |
| --- | --- |
| Disconnected | Nothing is routed; you are on the network you are physically on |
| Connecting… | Setting up the encrypted tunnel |
| Connected | Traffic is going through your vploq, and the label becomes a running timer |
| Disconnecting… | Tearing the tunnel down |
| Error | Something failed. The app shows why, then returns to Disconnected |

Once you are connected, the status line turns into a live timer showing how long
the connection has been up.

## Direct and relayed connections

Once connected, vploq uses the best path it can find between your app and your
device. There are two, explained in full under
[how vploq works](/learn/how-vploq-works#the-two-paths).

A direct connection is peer to peer, and the traffic does not pass through
vploq's infrastructure at all. It is the better path, and the app prefers it
whenever the network allows. When a direct path is live, the app shows a
**Direct** indicator; while it is still trying to build one, that reads
**Establishing a direct connection**. (The indicator is shown on Windows and
Android today.)

A relayed connection is the quiet default: no direct path was possible, so an
encrypted relay forwards the packets. Most mobile networks and many corporate
firewalls make a direct connection impossible, so this is common and is not a
fault. There is no separate "relayed" badge, because a relayed connection is
simply one without the Direct indicator. Either way the tunnel is encrypted the
same, and switching between the two happens underneath you without dropping your
connection.

## Device access only

Sometimes the app marks the connection **Device access only**, meaning this
connection does not route your internet traffic. You can reach the things on
your home network, such as a printer, NAS or router, but your browsing goes out
through the network you are physically on rather than through your home.

This happens when the vploq you are connected to is shared with you rather than
owned by you, or when the device is not set up to act as an exit for internet
traffic. See [how vploq works](/learn/how-vploq-works#your-internet-or-just-your-devices).

## Connection errors

Errors appear briefly as a message and the app returns to Disconnected.

| Message | Cause |
| --- | --- |
| No internet connection. Reconnect to a network and try again. | The phone or laptop itself is offline |
| VPN permission is required. Open Settings to enable it. | The operating system needs permission to route traffic |
| Your access to this vploq has been revoked. | The owner of that vploq removed your access |
| Couldn't connect. Please try again in a moment. | Usually transient; try again shortly |

If one persists, see [troubleshooting](/support/troubleshooting).

## While you are offline

If your phone or laptop loses its own internet connection, the app keeps showing
your devices and teams from its last-known data and displays an **Offline —
using cached data** banner. You can look at things, but you cannot connect or
change anything until your connection comes back.
