Troubleshooting
What to do about the specific things that actually go wrong, beyond the eight connection states.
The connection states table is the first thing to check — the app names a state, what it means, and what to try, and covers most of what follows in more depth than this page repeats. This page is for the handful of situations that show up before a state does, or that the table's one-line advice doesn't quite cover.
| If this is happening | Try this |
|---|---|
| The app looks stuck right after install, on a Mac | System Settings → Privacy & Security — approve the system extension. The app names this outstanding rather than silently failing, but it's easy to miss the banner. |
| A pairing code says it's invalid or expired | Codes are short-lived on purpose. Go back to Pair on the device with no keyboard and get a fresh one — nothing about the first attempt needs undoing. |
| It connects, then drops the moment the screen locks or the laptop sleeps | Reconnect once the device wakes. This is expected on a network that changes underneath the tunnel (Wi-Fi to cellular, a laptop resuming); the app doesn't yet resume a session across it. |
| Everything is slow, not just blocked | See Degraded in the states table — usually the network you're on, not the tunnel. Try another location. |
| Nothing on the device works, not just the VPN | That's UnderlayDown — your own network is down. Nothing further out can be tested until it's back; this isn't a ForestVPN problem to diagnose yet. |
| You've run out of things to try | Write to us with a support code from Account → Get help. Never include your account number — support doesn't need it and shouldn't ask for it. |
If it's the account, not the connection
- Lost the account number, or not sure a device still has it? See the account number — read it before writing in, since it explains exactly what can and can't be recovered.
- Need to put your subscription on a new or second device? See devices and linking.
- Hit the free tier's limits sooner than expected? See the data allowance.
What "the app has already done the diagnosis" means
The eight states aren't a guess dressed up as a diagnosis — each one names the layer the fault was
observed at (your network, the handshake, the tunnel itself, the exit server) and the app won't
report a state it doesn't have evidence for. If you see Unknown, that's the app being honest that
it doesn't have enough evidence to name a layer yet, rather than guessing and moving you to a
different server for a problem that might be sitting on your own network.