Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 806

Bitdefender VPN error 806: the tunnel drops or refuses to start at all

12 min read Updated October 4, 2026 Antivirus & Endpoint Security

Fix it now

806 is a Windows remote access error and Microsoft’s published meaning is specific: a device between you and the VPN server is not allowing Generic Routing Encapsulation packets. GRE belongs to PPTP, and Bitdefender publishes WireGuard and Hydra as its VPN protocols – so this number is coming from a Windows VPN connection profile, not from the Bitdefender client.

Elevated PowerShell – substitute the endpoint you are trying to reach

Test-NetConnection <server> -Port 443
  1. Open Settings, Network & internet, VPN and see what connections are listed there. A three-digit remote access error comes from one of those, not from the Bitdefender VPN window.
  2. If the connection you actually care about is the Bitdefender one, read the traffic counter on the app’s main screen. The VPN bundled with the antivirus suites is traffic-limited, and no network troubleshooting helps once the allowance is spent.
  3. Switch to a different country in the server list and connect again. A single overloaded or blocked endpoint is a common cause.
  4. In the VPN app’s settings, change the connection protocol if your build offers a choice, and prefer a TCP-based option on restrictive networks.
  5. Test the path with the command above. A failure there is a firewall, not the app.
  6. If it still fails, uninstall Bitdefender VPN, restart, and reinstall it so the virtual adapter is registered cleanly.

Do not go looking for a PPTP passthrough setting to make Bitdefender VPN work. Bitdefender’s VPN runs over WireGuard and its Hydra protocol; neither uses GRE, so a passthrough setting has nothing to act on.

If the tunnel comes up and holds through a reconnect, you are done. If not, the next section separates the two problems this page covers.

Why it happens

Two different failures hide behind one search, and mixing them up is why this takes an evening. One is a Windows remote access error. The other is a Bitdefender VPN that connects and then stops. They share no cause and no fix.

Take the code first. Microsoft publishes 806 as ERROR_VPN_GRE_BLOCKED: a connection has been started but cannot be completed, most commonly because an internet device between you and the VPN server is not configured to allow Generic Routing Encapsulation packets. GRE is the encapsulation PPTP uses, and Bitdefender publishes its VPN as running over WireGuard and the Hydra protocol – neither of which carries traffic in GRE. A Bitdefender tunnel has no way of producing 806.

That does not make the number meaningless. It means the failing connection is a Windows VPN profile: a manually created PPTP connection, a work tunnel, or something left behind by a product that has been removed. Settings, Network & internet, VPN is where those live, and that is where 806 is answered – by getting GRE permitted on the path, or by moving that connection to a protocol the network does not filter.

The other failure is the metered one. The VPN bundled with Bitdefender’s antivirus suites carries a daily traffic allowance, and when it is spent the tunnel stops carrying traffic – which people reasonably mistake for a connection fault. Read the counter on the app’s main screen. Bitdefender’s unmetered offering is Premium VPN, published as unlimited encrypted traffic on up to 10 devices and included in Premium Security and Ultimate Security.

The number is coming from a Windows VPN connection, not from Bitdefender

You have this one if 806, 812, 619 or 633, raised from Settings, Network & internet, VPN rather than from the Bitdefender VPN window.

  1. List what is under Settings, Network & internet, VPN and remove entries left by products you no longer use.
  2. For a PPTP connection you actually need, ask the network owner to permit GRE – IP protocol 47 – along the path. Many consumer routers and hotel networks do not forward it at all.
  3. Where you cannot change the network, move that connection to a protocol that rides over a common TCP port.
  4. Connect Bitdefender VPN from its own window and confirm it behaves independently.

The daily traffic allowance is spent

You have this one if The Bitdefender tunnel connects, works briefly, and then stops carrying traffic. The counter on the app’s main screen shows the allowance used.

  1. Read the traffic figure on the VPN app’s main screen and compare it with the allowance shown beside it.
  2. Wait for the daily reset, or switch the VPN off for browsing that does not need it and keep the allowance for what does.
  3. If you use the VPN daily rather than occasionally, move to the unmetered entitlement instead of rationing.

Bitdefender does not currently publish the allowance figure on its VPN product page, so read the number the app shows you rather than one you found online.

The server refuses the connection on policy grounds

You have this one if 812, raised from a Windows VPN connection.

  1. Read Microsoft’s meaning literally: a policy on the RAS or VPN server prevented it, and specifically the server’s authentication method may not match the one in your connection profile.
  2. Compare the authentication settings on the connection with what the gateway expects.
  3. On a corporate tunnel this is a question for whoever runs the gateway.

The virtual adapter is in use or misconfigured

You have this one if 619 or 633 rather than a clean 806, or Device Manager shows a VPN or WAN Miniport adapter with a warning icon.

  1. Microsoft publishes 633 as the specified port already being in use or not configured for remote access dial-out, and 619 simply as the specified port being disconnected.
  2. Open Device Manager, expand Network adapters, right-click any adapter showing an error and choose Uninstall device, then Action, Scan for hardware changes.
  3. If that does not restore it, uninstall Bitdefender VPN from the installed programs list, restart, and reinstall.
  4. Restart again and connect before launching anything else, so nothing has claimed the adapter first.

Another VPN or security product owns the network path

You have this one if A second VPN client, a corporate endpoint agent or a third-party firewall is installed, and the Bitdefender tunnel fails while the other one works.

  1. Disconnect and fully exit any other VPN client, then try again. Several cannot share a route table sensibly.
  2. Stop a third-party firewall briefly to test. If the tunnel then builds, add an allow rule for the VPN client rather than leaving the firewall off.
  3. On a work laptop, expect a managed endpoint agent to win. That is deliberate.

Do not leave a third-party firewall disabled after testing. Re-enable it and add a rule for the VPN client instead.

Full reference

The four remote access codes in full

Code Constant Published meaning
806 ERROR_VPN_GRE_BLOCKED A connection has been started but cannot be completed, most commonly because a device between you and the VPN server is not configured to allow Generic Routing Encapsulation packets
812 ERROR_SERVER_POLICY The connection was prevented because of a policy configured on your RAS/VPN server; specifically the server’s authentication method may not match the one in your connection profile
619 ERROR_PORT_DISCONNECTED The specified port is disconnected
633 ERROR_PORT_NOT_AVAILABLE The specified port is already in use or is not configured for remote access dial-out

All four are Windows remote access codes. Bitdefender publishes none of them, which is the fact that reorganises this entire problem: if your screen shows one of these, look at what is under Settings, Network & internet, VPN before you touch the Bitdefender client.

What Bitdefender publishes about its own VPN

Claim Bitdefender’s published wording
Protocols WireGuard, described as the newest and fastest VPN protocol on the market, and the Hydra protocol on all platforms
Encryption 256-bit AES, or the highest available cipher supported by both client and server, with Perfect Forward Secrecy
Unmetered tier Bitdefender Premium VPN – unlimited encrypted traffic on up to 10 devices
Where Premium VPN is included Bitdefender Premium Security and Bitdefender Ultimate Security

Note what is not in that table: any daily allowance figure for the VPN bundled with the antivirus suites. Bitdefender’s current VPN page does not publish one, so the honest answer is that the bundled VPN is traffic-limited and the app shows you the number. Read the counter rather than a figure from a comparison article.

Which problem you have, in one test

  1. Tether the PC to a phone and try the Bitdefender VPN. If it comes straight up, the fixed network was filtering it and there is nothing wrong with the client.
  2. If it connects everywhere and then stops after a few minutes of use, read the traffic counter. That is the allowance, not a fault.
  3. If the failure is a three-digit number, open Settings, Network & internet, VPN. Whatever is listed there is what produced it.
  4. If Bitdefender VPN itself refuses on every network including mobile, uninstall and reinstall it, then sign in again.

If you go on to reset the network stack with netsh winsock reset and netsh int ip reset, understand that both reset network configuration to defaults and require a restart. Note any manual network configuration first, and do not run either on a machine you cannot reach physically.

Where GRE actually matters

GRE is IP protocol 47, and it is not a TCP or UDP port – which is why many consumer routers, hotel networks and captive portals drop it silently rather than blocking it visibly. A PPTP connection needs it forwarded end to end. If you are maintaining such a connection deliberately, the router setting to look for is usually labelled VPN passthrough or PPTP passthrough. If you are not, the modern answer is to stop using PPTP: a protocol that tunnels over TCP 443 looks like ordinary encrypted web traffic and survives most filtering.

Before you blame the client

  • Confirm the internet works with the VPN disconnected.
  • Try two or three different server locations rather than one.
  • Exit every other VPN client fully, not just disconnect it.
  • Test the endpoint with Test-NetConnection <server> -Port 443 from an elevated PowerShell prompt.
  • Check whether the machine is on a managed network with an endpoint agent that is designed to win. That is a conversation, not a configuration change.

When a licence is the actual fix

If the tunnel stops because the bundled allowance is spent, no amount of network troubleshooting will fix it – the cap is doing what it was designed to do, and the counter on the app’s main screen is the evidence. The unmetered answer is Bitdefender Premium VPN, which Bitdefender publishes as unlimited encrypted traffic on up to 10 devices and which is included in Bitdefender Premium Security and Bitdefender Ultimate Security rather than sold as a separate subscription alongside them. Arco supplies Bitdefender Premium Security and can confirm which device count fits your machines. Two honest alternatives: standalone VPN services exist and are worth comparing, and if you only need a tunnel occasionally the bundled allowance is already paid for and adequate. If your problem turned out to be a three-digit Windows remote access code, none of this applies – that is a different connection and there is nothing to buy.

Every code this article covers

Code What it points at Source
806 ERROR_VPN_GRE_BLOCKED – a device between you and the VPN server is not allowing Generic Routing Encapsulation packets. GRE is used by PPTP; Bitdefender VPN uses WireGuard and Hydra Microsoft Learn
812 ERROR_SERVER_POLICY – the connection was prevented by a policy on the RAS or VPN server, typically an authentication method mismatch Microsoft Learn
619 ERROR_PORT_DISCONNECTED – the specified port is disconnected Microsoft Learn
633 ERROR_PORT_NOT_AVAILABLE – the specified port is already in use or is not configured for remote access dial-out Microsoft Learn

Confirm the fix worked

  1. Bitdefender VPN reports the tunnel as established, with the selected country shown.
  2. A site that reports your public IP address shows the VPN location rather than your own connection.
  3. The traffic counter on the app’s main screen moves during normal use rather than sitting still.
  4. Settings, Network & internet, VPN contains only connections you actually use.
  5. Disconnect, reconnect and confirm the tunnel comes up first time without a network reset.

Questions people ask about this

Is error 806 caused by Bitdefender?

No, and it cannot be. Microsoft publishes 806 as GRE being blocked on the path, and GRE is what PPTP uses. Bitdefender publishes its VPN as running over WireGuard and the Hydra protocol, neither of which uses GRE. The failing connection is a Windows VPN profile.

Does buying a bigger Bitdefender licence remove the traffic cap?

Only if the edition you buy includes the unmetered VPN. Bitdefender publishes Premium VPN – unlimited encrypted traffic on up to 10 devices – as part of Premium Security and Ultimate Security. Adding more devices to a suite that bundles the metered VPN gives you the same metered VPN on each of them.

How much traffic does the bundled VPN give me?

Read the counter in the app. Bitdefender does not publish an allowance figure on its current VPN product page, so any specific number you find in an article is not something you should rely on when the app will tell you exactly.

Why does the VPN work on my phone and not on this PC?

Almost always because the phone is on a mobile network that forwards the tunnel and the PC is on a network that filters it. Tether the PC to the phone for one test; if the tunnel comes up, the fault is the fixed network.

Will switching protocol slow the connection down?

Tunnelling over TCP is usually slower, because you end up with one reliable transport carried inside another. It is a trade for connecting at all. Switch back to the automatic setting on networks that allow it.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error Trend Micro says your subscription has expired and protection has stopped License Error Avast subscription expired: fixing activation errors 0xE001D025 and 0xE001D024 Free Fix Microsoft Defender error 0x80508023: the threat was no longer there to remove Free Fix ESET error ECP.20001: activation server cannot be reached from this network
โ† Back to Knowledge Base