
You switched ISPs. Same street. Same kitchen. A new modem or ONT on the shelf, maybe a fiber overlay while the old copper is still in the wall. The old carrier's SSID is still in every phone. Either the five devices join the new name and the tunnel still means what you meant, or they sit on the retired box until the technician carts it away. Ranked listicles will mash this week into a router you bought, a move with cardboard, a CGNAT physics lecture, and the standing home-Wi-Fi thesis until the affiliate cookie expires. This page is smaller. You did not change addresses. You changed the last mile under the same roof.
This is not VPN When Replacing a Router: Same House, New Box, Forget the Old SSID. That URL is a new box you picked, same ISP account most weeks, a sticker you bought. Stay there if the bill still says the old carrier and you only swapped plastic. This is not VPN After Moving House: New ISP, New Router, Same Five Seats. Cardboard, two buildings with power, often a new ISP because the address changed. Here the plot is one address and a new account number. This is not Cgnat: Not a VPN Setting. That essay owns shared IPv4, inbound ports, why a hop does not give you a public door. I will point at leftovers. I will not clone the physics. This is not Do You Need a VPN on Home Wi-Fi?. That is the standing thesis on a LAN you already live on. Here the observer on the last mile just changed names.
HTTPS already encrypts the page on most of the sites you actually use. The lock in the browser is real. A VPN still wraps the path from a device to a server you picked. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. It is not a tunnel and it is not a forget-network checklist. Encrypted Client Hello exists in the industry and is uneven. Do not pretend the lock hid the graph. Do not pretend a new SSID hid the graph from the new carrier. The last mile still sits on the path until you wrap it.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. The laptop is one seat when the tunnel is up. Phone plus laptop is two. A tablet still hunting the old modem name will not help you. Download is the apps. There is not a new-ISP SKU. There is not a fiber coupon. Pricing is the live number. Smart Connect, if the app shows the row, means connect on untrusted Wi-Fi. The old home SSID was yours. The new one is a new string. Mark it however the app lets you. Cookies on this site live at /cookie. I will not invent a city count as a reason the overlay is special. I will not invent a consumer firmware SKU. I will not invent a custom DNS picker so this article matches a competitor screenshot. Features lists DNS through the VPN tunnel, IPv6 leak protection, and WebRTC leak blocking. Trust those sentences after Connect is up.
I have a bias. Forget the old ISP gear SSIDs. Rejoin. Confirm tunnel DNS. IPv6 and CGNAT leftovers are siblings. Point at those essays. Do not clone them. Five devices each need the new Wi-Fi. The seven-day window is first purchase, not an ISP promo. Do not flash a leased modem against the lease. Do not clone the moving-house essay onto a cutover in the same hallway. Count seats while every phone is still hunting a name the old carrier left behind.
Related reading: IPv6 Leak in Plain English: Two Addresses, One Laptop and What is a VPN?. Android VPN setup and iOS VPN setup.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Same house, new carrier
A router you bought is a new radio on the same last mile. A move is cardboard and two buildings. CGNAT is how a lot of ISPs stretch IPv4. Home Wi-Fi is whether you wanted a hop on a LAN you already live on. Switching carriers at the same address is none of those. The street did not change. The account number on the bill did. The modem, the ONT, or both did. New default name. New password on a sticker the technician left on the fridge. New DHCP pool. Sometimes a v6 prefix the old cable brick never offered. Sometimes a shared public IPv4 the old DSL line never used. Your Klox install is still the same binary. The observer under it is a different company.
People treat a new ISP as the same house with a faster download number. Same kitchen, same year, not really a network. The phones disagree. They still list the old modem SSID as saved. They still try it first. They still skip the tunnel because last month that name was trusted. Farms skip that sentence because the keyword is home. Home after a carrier change is a new last mile, then a habit you already had, then a test.
Fiber overlay is the messy cousin. The truck hangs an ONT. Copper or coax may still sit in the wall for a week. Two radios can live in one hallway if you leave the old gateway powered. That is not a mesh you designed. That is two last miles arguing. Unplug the retired box once the new one actually routes, or you will spend an evening debugging a tunnel that is fine while the laptop is still on the dead carrier.
I will not walk packet sniffing. The public Wi-Fi how-to already did. I will not pack your chargers. You did not move. I will not sell you a preconfigured closet box. I will not name a consumer firmware SKU we do not ship. Cloudflare's IPv6 explainer is what a lot of overlays turn on by default. It is not a VPN. It is not Klox.
Klox is a consumer tunnel to an exit you picked. It is not the new ISP's activation disc. It is not the ONT on the wall. It will not inherit a trusted-network flag from the old modem SSID unless you told the app the new name is also yours. Treat the first handshake on the new last mile as a first handshake, not as a continuation of last year's cable bill.
- 1Join the SSID. Do not start the VPN yet.
- 2Open a browser and finish the captive portal.
- 3Open Klox. Connect WireGuard.
- 4If the handshake dies, switch to OpenVPN. Then work.
Do this in order
| Moment | What changed | VPN habit | This page? |
|---|---|---|---|
| Same house, same ISP, same box | Nothing last-mile | Home-Wi-Fi thesis: want versus need | No, that article |
| Same house, same ISP, new router you bought | SSID, DHCP, maybe IPv6 | Forget old name, rejoin, leak test | No, replacing-router article |
| Same house, new ISP or fiber overlay | Last mile, modem or ONT, maybe CGNAT, maybe v6 | Forget old ISP gear SSIDs, rejoin, confirm tunnel DNS | Yes |
| New house, cardboard | Address, often the ISP too, two buildings with power | Moving-house article | No, that article |
| CGNAT physics | Shared public IPv4, inbound fails | CGNAT essay | No. Point, do not clone |
| Old modem SSID still in device memory | Saved radio from the retired carrier | Forget it on every seat | This page |
| New ISP hands IPv6, old did not | Dual-stack old | Test IPv6 leak protection | This page, plus the leak article |
Same street. New carrier. Forget the old ISP gear SSIDs. Rejoin. Confirm tunnel DNS.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
Wikipedia: Virtual private network
Fiber overlay is not a move
The truck added a last mile. The furniture stayed. Two radios in one hallway is a cutover mess, not cardboard. Unplug the retired modem once the new path actually routes.
Farms mash every home keyword
Need a VPN at home, moving, new router, new ISP: one ranking, one cookie. A carrier change in the same kitchen is a new last mile and a test. Treat the ranking as a specimen, not a wizard.
Forget the old ISP gear SSIDs
The old modem name is still in every device that ever joined it. Phones offer it first. Laptops auto-join a neighbor if the password was a vendor default you never changed. Tablets sit in a saved-network list until you prune them. Forget it on purpose. Windows, macOS, iOS, Android: open the known-networks list and delete the dead string. Then join the new one from the sticker, or from the new ISP app, or from the sheet the technician left.
If you leave the old name saved, two ugly things happen. The device hunts a radio that is off, fails, and looks like the internet is dead. Or a neighbor still uses a similar default name and you join their LAN because the password was the vendor string printed on a million boxes. Finish whatever splash they have. Then leave. Do not treat the first Wi-Fi name that sorts to the top as the house.
Return-the-modem day makes this worse. The old box still broadcasts until you unplug it. If you forget the SSID after you drop the hardware at the store, a neighbor with the same vendor default can look like home. Forget the name while the retired box is still in your hallway, then unplug it, then join the new sticker. Order matters.
I will not paste OS click-paths that rot next autumn. Search the settings app for known networks, saved networks, or Wi-Fi. Delete the old ISP gear SSIDs. Confirm the new one. Then open Klox. Then Connect. WireGuard first.
A VPN does not forget networks for you. Smart Connect does not delete a saved SSID. The OS list is furniture. You own the broom. Do this on all five seats, not only on the laptop you used to email the new carrier. The phone in a kid's bag still has the old name. That is how people invent a curse about the new ISP blocking VPNs. The phone never joined it.
Unplug the retired modem, then forget the name
Do not rename in your head. Delete the old string. Join the new one from the label on the ONT, or from the ISP app. Guessing is how you land on a neighbor, or on a box you already returned.
Every seat, not one laptop
Five devices each need the new Wi-Fi. A forgotten tablet on the old modem name is not tunneled. It is also not on the new LAN. Forget, join, Connect, in that order.
CGNAT leftover and IPv6 leftover are siblings
A new fiber shop often puts you behind carrier-grade NAT. Your laptop thinks it has a private number. The internet sees a shared door. Inbound ports fail because that door is not yours to open. A VPN does not undo that. It changes the hop you leave through. Sites see a VPN exit instead of the ISP door. Consumer exits are shared too. You still are not hosting inbound. The Cgnat: Not a VPN Setting owns that physics. This page exists so you do not declare WireGuard dead because a game server could not punch a hole the afternoon the overlay went live.
IPv6 is the other leftover. Dual-stack shows up because the new wizard left it on. A v4-only tunnel without a block can leave the v6 path on the NIC. Features lists IPv6 leak protection as a block. Test it. Do not file a ticket that the new ISP broke VPN because a test page showed a prefix you did not have on copper. The IPv6 Leak in Plain English: Two Addresses, One Laptop article owns the clicks. This page exists so you do not skip the test after a cutover.
They are siblings, not clones. Crowded v4 is a sharing story. Missed v6 is a leftover-path story. DNS is a third chore. Farms mash all three into one screenshot of Fastest server. Do not. If inbound failed off-tunnel, that is CGNAT. If a test page still shows a v6 after Connect, that is a leak test. If names still resolve at the ISP resolver after Connect, that is tunnel DNS. Three desks. Three URLs. One afternoon, then stop.
Baseline with the VPN off so you know what this carrier looks like in the clear. Write down the v4. Note whether v6 exists. Then Connect. Then the same tools. A pass is this browser, this network, this moment. It is not a character reference for the old cable plant.
I will not invent a dedicated-IP SKU so this article can pretend you got a public door back. I will not invent a city count as a reason CGNAT is special. I will not paste adapter checkboxes so this URL competes with the leak how-to. Point. Test. Move on.
Shared IPv4 is not a broken VPN
Inbound failed off-tunnel too. That is the CGNAT essay. Connect still wraps outbound. Do not spend cutover night flashing a leased ONT because a console could not host.
v6 showed up because the overlay left it on
Old brick was v4-only. New fiber delegates a prefix. Dual-stack is default on a lot of overlays. Test IPv6 on purpose. The leak article owns the clicks.
Rejoin, then confirm tunnel DNS
Join the new SSID first. Finish the new ISP's welcome garden if the browser hangs on their activation page. Then open Klox. Then Connect. WireGuard first. OpenVPN when that welcome page hates UDP. Switching protocols while the splash is unfinished wastes twenty minutes and invents a story that the new carrier blocks VPNs.
Default DNS on a new gateway is the ISP's resolver until you change it, and a consumer VPN that actually connected still wants DNS inside the tunnel. Features lists DNS through the VPN tunnel. I will not invent a custom DNS picker in the Klox app so this article matches a competitor screenshot. Trust that sentence after Connect is up. Do not spend cutover day hunting a lab row.
If names still resolve at the new ISP's resolver after Connect, you are not testing leaks. You are testing a client that did not take the route. Reconnect. Confirm the app says connected. Load a plain site. Then run the Leak Test After You Connect a VPN: IP, DNS, WebRTC, IPv6. Do the check on the laptop and on a phone. Cutover week is when people only test Chrome on the machine they used to read the ISP email. The tablet on the counter is a different stack.
The sticker on the modem is not tunnel DNS. The ISP app's recommended resolver is not tunnel DNS. Private DNS on Android is a different argument the Android Private DNS vs a VPN: DoT Hostname Versus Tunnel DNS page already owns. Here the job is smaller. After Connect, names should follow the tunnel. If they do not, stop. Fix the client. Then continue.
Cellular on a phone is a valid afternoon skip while the technician is still in the hallway and the copper is dead. That is not a leak. That is a radio. When the new Wi-Fi actually routes, rejoin, then confirm tunnel DNS on purpose. Do not treat LTE as proof the house is done.
Activation garden before protocol panic
If nothing loads, you are in the new ISP garden. Complete it. Then WireGuard. OpenVPN if UDP is rude. Switching protocols while the splash is unfinished wastes the evening.
Tunnel DNS is not the gateway sticker
ISP resolver on the WAN is expected until Connect. After Connect, names should follow the tunnel. If they do not, you are not testing leaks. You are testing a client that did not take the route.
Two boxes in one hallway
Fiber overlay week often leaves the old gateway powered because nobody wanted to kill the old SSID until the new one proved itself. That is reasonable for an hour. It is not a plan. Two DHCP servers, two default names, two paths to the internet, and a laptop that still prefers last year's string. Unplug the retired box once the new last mile actually works. Do not run both as two homes.
If you kept your own router behind the new ONT, that is a different sentence. Bridge the ISP modem if they allow it. If they do not allow it, you have double NAT. Outbound still works. Inbound was already a CGNAT problem on a lot of fiber. A VPN still wraps the hop from the device. Putting Klox on the closet box is a lifestyle choice the Router VPN vs Per-Device Apps article already owns. This page will not clone it. Cutover week only adds: the new box is often an ISP-rented gateway. If the lease says you may not alter the firmware, you may not alter the firmware. Put the apps on the devices you carry.
Smart Connect, if the app shows the row, means connect on untrusted Wi-Fi. The old home SSID was probably marked trusted, or excluded, because you lived on it. The new SSID is a new name. If you wanted the tunnel on house Wi-Fi, confirm the new name is in the habit you meant. If you wanted the tunnel only on cafes, confirm the new name is not treated like a shop just because it still says the vendor on the sticker.
Always-on on a phone does not know you changed carriers. It will try to hold a peer on the new radio the same way it did on the old one, once the phone actually joins. That is usually what you wanted. It is also how a tablet that never joined the new name still looks idle while you think the house is covered.
Windows and macOS trusted-network lists are OS furniture, not Klox SKUs. If the laptop auto-joins a leftover mesh node you unplugged, you joined a radio that is gone. If it auto-joins a neighbor, you joined a LAN you do not run. Finish whatever splash they have. Then tunnel, or leave.
If the Smart Connect row is missing in the app, you have a Connect button. Use the button after you have a real route. Do not perform a portal ritual that is not there. Load a plain site. If it hangs on the new ISP welcome page, you are still in their garden. Complete it. Then Connect. WireGuard first. OpenVPN when that welcome page hates UDP.
I will not coach flashing leased gear
No OpenWrt on an ISP modem you do not own. No recovering a brick the new carrier will bill you for. Per-device apps from /download. A router you own is a different purchase and a different article.
New name, old habit
The trusted or untrusted flag lived on the old modem SSID string. Re-teach the app. Do not assume last year's cable exception followed the ONT.
Five devices each need the new Wi-Fi
Klox is five simultaneous connections. Install can be more. Connect cannot. A carrier change does not grow the plan. It also does not shrink it. What it does is leave three phones on the old modem name and two on the new one, so you think the house is half-tunneled when half the house is still hunting a ghost.
Walk the list. Laptop. Phone. Partner phone. Tablet. The desktop that never sleeps. Forget old ISP gear SSIDs. Join new SSID. Open the app. Connect if that is the habit you wanted at home. Sleep is not disconnect. A lid on the desk can keep a peer. Open the app and look. Remove retired devices in the account UI when the old phone is actually in a drawer. I will not invent a portal URL. Use the account page you already use.
A router you left holding a tunnel, if you ever ran one, still counts as one seat until it loses power or you disconnect it. The new ONT is not automatically that seat. Do not assume a mesh node inherited the old handshake. It did not. The old ISP gateway you stuffed in a bag still might, if you never powered it down with the peer up. Unplug it. Then look at the account.
Phone plus laptop at the kitchen table is two. That is the usual first night after a cutover. Do not tunnel every gadget you have not named yet. Five is enough for a household that actually carries computers. It is not a seating chart for bulbs.
IoT you dumped on Guest because a blog said to still cannot run our app. The camera can wait, or it can sit on Guest without a consumer VPN, which is how most bulbs live anyway. Helpers assembling the ONT do not need your Klox login. Isolation first. Their app, their account, if they even needed a hop. Change the Wi-Fi password. Change the admin password. Turn on WPA2 or WPA3 as the box offers it. Those are owner jobs when the lease lets you into the admin page. They are not a VPN. A VPN is not a firmware update.
Ghost names steal evenings
A tablet offering the old modem SSID looks like a dead internet. Forget the name. Join the new one. Then worry about Connect. Order matters.
The plan did not change because the bill did
Yearly from $2.83 a month is still five seats. A new carrier is not a sixth. Disconnect what is not in this bag, or live with the error when the sixth handshake tries.
Leak test on the new last mile
Connected is a UI state. The new carrier has not agreed until you check. After the first handshake on the new SSID, run the after-connect checklist: IP, DNS, WebRTC, IPv6. Baseline with the VPN off so you know what this house looks like in the clear on this ISP. Then connect. Then the same tools.
If the address did not change after Connect, stop. You are not testing leaks. You are testing a client that did not take the route. Reconnect. Try OpenVPN if WireGuard is stuck on an ISP welcome page. Complete the garden first. Then continue.
IPv6 is louder on a lot of fiber overlays than on the cable brick you stuffed in a bag. Dual-stack shows up because the wizard left it on. A v4-only path without a block can leave v6 on the NIC. Test it. Do not file a ticket that the new ISP broke VPN because a test page showed a prefix you did not have last month.
WebRTC can still offer a local candidate if a browser is rude. Features lists WebRTC leak blocking. Run the checklist on more than one browser if you can stand it. Do the check on the laptop and on a phone. Cutover week is when people only test the machine they used to chat with support. The tablet on the counter is a different stack.
If inbound still fails off-tunnel, that is not a leak. That is CGNAT, or double NAT, or both. Read the CGNAT essay. Do not keep reconnecting as a ritual. A leak site prints an IP. It does not print a NAT type. One afternoon, then stop. I will not paste adapter checkboxes so this URL competes with the test how-to. This page exists so you do not skip the test because the street did not change.
Baseline on this carrier
VPN off, What is my IP, write it down. That is this ISP. Then Connect. The address should move. The old screenshot from the cable years is not a baseline.
A leak site does not print NAT type
If inbound still fails off-tunnel, that is CGNAT or double NAT. Reconnecting as a ritual will not open a public door. One afternoon of IP, DNS, WebRTC, IPv6. Then stop.
Seven days is not an ISP coupon
If you bought Klox only because a home-VPN farm said a new ISP requires a new brand, the consumer window is seven days on first purchase. Live page: /refund. Renewals are not that window. Store purchases follow the store. I would rather you keep the year if the habit already existed on the old last mile. Yearly from $2.83 a month is not a hardware tax. A new carrier is not a new SKU. The seven-day window is not a fiber promo and it is not an ISP coupon.
Cookies on this site live at /cookie. The new modem's portal cookies are the ISP's. Do not mix those desks when you are hunting a privacy page at midnight. Our cookie URL is /cookie. It is not a policy about the ONT sticker.
WireGuard first on the new radio. OpenVPN when the ISP's welcome page or a rude AP hates UDP. One change, test a site, stop. If both fail, it is the garden, the kill switch, or a client that is still aimed at a network that does not exist. Cellular on a phone is a valid first-night skip while the technician is still in the hallway.
Do not buy a month of a farm brand because a best VPN for home list told you a carrier change requires a reset, then also keep Klox, then refund neither. Pick one tunnel. Five devices is enough. You do not need a city count to sit in a kitchen that still has the old modem in a bag.
Change the Wi-Fi password on a gateway you are allowed to administer. Change the admin password. That is hygiene. It does not replace a tunnel. It also does not require a custom firmware image we do not sell. Sticker passwords are not a personality. The new ISP's default name is not yours until you rename it, and renaming it does not hide the graph from the new last mile. HTTPS already locked the page. The carrier still sees the hop unless that hop is a VPN.
First purchase, not a fiber promo
The seven-day window is so you can try the apps. It is not a gift because the bill changed carriers. If you already used a first purchase on the old last mile, you already used the window.
Our cookie page is /cookie
Site cookies: /cookie. ISP gateway cookies: theirs. A tunnel does not delete those. It also does not require a second privacy URL with a different slug.
Key Takeaways
You switched ISPs at the same address, or you took a fiber overlay while the furniture stayed. That is a new last mile, not a new Klox product and not a reprint of the moving-house essay. It is also not a router you bought on the same account, and it is not the CGNAT physics lecture. Forget the old ISP gear SSIDs. Rejoin. Confirm tunnel DNS. Confirm Smart Connect still means what you meant. Leak-test IP, DNS, WebRTC, and IPv6 on this carrier. HTTPS already locked the page. The new ISP still sees the hop unless that hop is a VPN. Do not flash a leased modem. IPv6 and CGNAT leftovers are siblings. Point. Do not clone.
Laptop is one of five. Phone plus laptop is two. A tablet still hunting the dead modem name is not tunneled. Five devices each need the new Wi-Fi. WireGuard first. OpenVPN when the welcome page is rude. Seven days if you bought only because a farm told you a new carrier needs a new brand. That window is first purchase, not an ISP coupon. Yearly from $2.83 a month. No city count. No custom DNS picker. No consumer firmware SKU. Cookies at /cookie.
If you wanted a box you bought on the same bill, that essay is next door. If you wanted cardboard and two buildings, that essay is next door. If you wanted shared IPv4 physics, that essay is next door. If you wanted want versus need on a house you already live in, that thesis exists. If you wanted a tunnel you will actually use the week the last mile changed names, download the apps, teach them the new SSID, and prove the hop before you return the old modem.
Related Resources
Forget the old modem SSID. Teach the apps the new last mile.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. Same apps from /download. New ISP, same house. No fiber SKU. Leak-test after the first handshake.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.