Fix it now
628 is a Windows connection error, not a Kaspersky one: Microsoft publishes it as ERROR_DISCONNECTION, the specified port was disconnected. It says nothing about the traffic allowance, so read the counter yourself – the free version gives 200 MB a day, or 300 MB with the device connected to My Kaspersky.
ipconfig /flushdns
netsh winsock reset
netsh int ip reset
- Read the traffic counter in the VPN application first. Kaspersky’s figure can differ from the actual amount by up to 15 per cent, so treat a counter close to the limit as spent.
- Connect the device to My Kaspersky if you have not. Kaspersky documents an extra 100 MB a day for that, and 300 MB more with an active Kaspersky Plus subscription.
- Choose a different server location and connect again. One busy or blocked endpoint accounts for a lot of these.
- Test on a phone hotspot. If the tunnel builds there, the fault is the network you were on rather than the client.
- On a captive network, complete the portal sign-in in a browser before starting the VPN.
- Run the reset commands above, restart, and try once more before reinstalling anything.
The allowance is per device. A licence covering several machines does not give them a shared pool, so the fifth device in the house has its own daily figure rather than a share of one.
If the tunnel comes up and stays up, you are done. If not, the next section explains what each of these codes is actually reporting.
Why it happens
A tunnel comes up in stages: resolve the endpoint, open a session, authenticate, negotiate the data channel. 628 lands at the point where the far end hangs up. Microsoft’s published text is short and worth taking literally – the specified port was disconnected – because it means the code carries no information about why. A server declining you and a network device killing the session look identical from the client.
That is why the traffic allowance is worth checking first even though the code does not mention it: it takes ten seconds and it is the most common single answer. Kaspersky publishes the free version as 200 MB of secure traffic per day when the device is not connected to My Kaspersky, an extra 100 MB a day once it is connected, and 300 MB more where there is an active Kaspersky Plus subscription. It also publishes a warning most people have not read: the traffic figure shown in the application can differ from the actual amount by up to 15 per cent.
If traffic is not it, the companion codes tell you which layer objected, and each has a published meaning. 651 is your modem or other connection device reporting an error, which points at the local adapter. 735 is the requested address being rejected by the server, which points at the far end. 807 is the connection between your computer and the VPN server being interrupted, and Microsoft attributes it to VPN transmission problems, internet latency or the VPN server having reached capacity – with reconnecting as the documented first action.
The daily allowance is spent
You have this one if The tunnel connects, works briefly, then drops repeatedly, and the counter in the application is at or near the daily figure.
- Read the traffic figure and compare it with the allowance the application shows for your version.
- Connect the device to My Kaspersky if it is not, which Kaspersky documents as adding 100 MB a day.
- Wait for the daily reset, or switch the VPN off for browsing that does not need it.
- If the tunnel is part of your daily routine rather than an occasional tool, move to the unlimited version instead of rationing.
Background sync, cloud backup and software updates all count while the tunnel is up. An allowance that disappears without obvious use is usually that.
The network will not carry the tunnel
You have this one if Every server location fails, and the same client connects immediately on a phone hotspot.
- Confirm with the hotspot test before changing anything on the machine.
- On a captive network, complete the portal sign-in first, then start the VPN.
- On your own router, enable any VPN passthrough option it offers.
- On a managed network, ask whoever runs it. Corporate networks block consumer VPNs deliberately and that is not a fault to fix.
The virtual adapter is in a bad state
You have this one if 651 appears rather than a clean 628, or Device Manager shows a network adapter with a warning icon.
- Open Device Manager and expand Network adapters.
- Uninstall any VPN or WAN Miniport adapter showing an error, then use Action, Scan for hardware changes.
- Reboot and connect before starting other software.
- If the adapter does not come back, reinstall the VPN application so its adapter is registered cleanly.
651 is published as the connecting device reporting an error. That is the local end, so a hotspot test will not clear it.
The server rejected the address, or is full
You have this one if 735 or 807 rather than 628, and the failure follows the location you choose rather than the network you are on.
- Choose a different server location. 735 is the requested address being rejected by the server.
- For 807, reconnect – Microsoft’s documented action – because it covers latency and the server having reached capacity.
- If one location fails consistently and others do not, stop investigating the client.
Another VPN or security product owns the route
You have this one if A second VPN client or a third-party firewall is installed, and only one of them works at a time.
- Fully exit any other VPN client rather than just disconnecting it, then try again.
- In a third-party firewall, add an allow rule for the Kaspersky VPN executable instead of turning the firewall off.
- Remove VPN clients you no longer use; each one leaves adapters and routes behind.
Full reference
The four numbers, and what Windows says about each
| Code | Symbolic name | Microsoft’s published text |
|---|---|---|
628 |
ERROR_DISCONNECTION | The specified port was disconnected |
651 |
ERROR_FROM_DEVICE | Your modem or other connection device has reported an error |
735 |
ERROR_PPP_REQUIRED_ADDRESS_REJECTED | The requested address was rejected by the server |
807 |
ERROR_VPN_DISCONNECT | The network connection between your computer and the VPN server was interrupted. This can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity |
None of these is a Kaspersky code. They belong to Windows’ remote access layer and any VPN client on the machine can raise them, which is a useful test in itself: if a second VPN fails the same way on the same network, reinstalling Kaspersky will not help.
The traffic figures Kaspersky publishes
| Situation | Secure traffic per day |
|---|---|
| Free version, device not connected to My Kaspersky | 200 MB |
| Free version, device connected to My Kaspersky | 300 MB |
| Device connected with an active Kaspersky Plus subscription | 300 MB more |
| Unlimited version | No limit |
Kaspersky states that the used-traffic figure shown in the main window may differ from the actual amount by up to 15 per cent. Do not treat a counter reading 180 MB as proof you have 20 MB left.
Working the network layer without guessing
- Test on a phone hotspot. This single test separates a client problem from a network one and takes a minute.
- If the hotspot works, the machine is fine. Take the question to whoever runs the network you were on.
- If the hotspot fails too, run the reset commands, restart, and test again.
- If it still fails, check Device Manager for a VPN adapter or WAN Miniport entry with a warning icon.
- Only then reinstall the application.
What the reset commands actually change
| Command | Effect |
|---|---|
ipconfig /flushdns |
Clears the resolver cache, so a stale answer for a VPN endpoint is discarded |
netsh winsock reset |
Resets the Winsock catalogue, removing layered service providers left by other software |
netsh int ip reset |
Rewrites the TCP/IP configuration to its defaults |
All three need a restart before they take full effect, and netsh winsock reset will remove third-party network components that some applications depend on. Do them together, restart once, and expect to re-check any other networking software afterwards.
Deciding whether the cap is your actual problem
- Note how long the tunnel stays up. Minutes rather than seconds, with normal traffic, points at the allowance.
- Note whether it fails at the same time each day. An allowance that resets daily produces exactly that pattern.
- Note whether it fails on every network including a hotspot. That points away from the network and towards the account or the client.
- Note whether other devices on the same subscription fail at the same moment. They should not, because the allowance is per device.
- Note what else is running. A cloud backup client will spend a day’s allowance in minutes without you touching anything.
If you decide to keep using the free allowance
It is a perfectly reasonable position for occasional use, and there are two things worth doing. Connect the device to My Kaspersky, because that is documented as increasing the daily figure and costs nothing. And turn the tunnel on for the things that need it rather than leaving it up, since everything the machine sends while it is connected counts, including updates and sync you did not initiate.
When a licence is the actual fix
If the tunnel keeps dropping because the daily allowance is not enough, nothing in the troubleshooting above applies – the cap is behaving as designed and no adapter reset changes it. The honest fix is an unlimited VPN entitlement. Kaspersky publishes an unlimited version of Secure Connection, and Kaspersky Premium is the consumer tier that includes it rather than metering it. That is one route among several: standalone VPN services exist and are worth comparing on price and on where their servers are, and if you use a tunnel occasionally the free allowance genuinely is enough. Arco can supply Kaspersky Premium and confirm what the edition includes for the number of devices you need before you commit.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
628 |
ERROR_DISCONNECTION: the specified port was disconnected. It reports that the session ended, not why, and carries no information about a traffic allowance | Microsoft Learn |
651 |
ERROR_FROM_DEVICE: your modem or other connection device has reported an error, which points at the local adapter rather than at the network | Microsoft Learn |
735 |
ERROR_PPP_REQUIRED_ADDRESS_REJECTED: the requested address was rejected by the server | Microsoft Learn |
807 |
ERROR_VPN_DISCONNECT: the connection between the computer and the VPN server was interrupted, commonly through latency or the server having reached capacity. The documented action is to reconnect | Microsoft Learn |
Confirm the fix worked
- The application reports the tunnel as established with the location you chose.
- Your visible IP address in a browser reflects the VPN location rather than your own.
- The traffic counter moves normally during a few minutes of use.
- Disconnect and reconnect once, and confirm the tunnel comes up first time without a network reset.
- Leave it connected for longer than the previous failures lasted, so you know the drop has actually stopped.
Questions people ask about this
Does error 628 mean I have run out of traffic?
No. Microsoft publishes 628 as ERROR_DISCONNECTION – the specified port was disconnected – and it carries no information about metering. The allowance is worth checking first because it is the most common cause, not because the code says so.
How much free traffic do I actually get?
Kaspersky documents 200 MB of secure traffic per day when the device is not connected to My Kaspersky, an extra 100 MB a day once it is, and 300 MB more where there is an active Kaspersky Plus subscription. It also notes the displayed figure can be out by up to 15 per cent.
Is 628 specific to Kaspersky?
No. It is a Windows remote access error and any VPN client can raise it. If a second VPN fails the same way on the same network, the network is the problem.
Why does it work at home and not at work?
Work networks commonly block consumer VPN traffic deliberately. That is a policy decision rather than a fault, and it is worth asking before trying to route around it on a machine your employer manages.
Does a bigger Kaspersky licence remove the limit?
Only if the edition includes the unlimited version of Secure Connection. Adding devices to a tier that bundles the limited VPN gives you the same daily allowance on each device rather than a shared larger pool.
