Start here: pick up a second device and try to join the same Wi-Fi. If your phone connects and the iPad doesn’t, the problem lives on the iPad. If nothing connects, stop troubleshooting the iPad and go look at the router. That one test cuts the possible causes roughly in half and takes fifteen seconds, and skipping it is why people spend an hour resetting the wrong thing.
Most Wi-Fi failures come down to about eight causes. A few are trivial. A couple — the ones involving older hardware and modern router security — are genuinely non-obvious, and they’re the reason a six-year-old iPad suddenly stopped connecting the week after someone swapped the router.
First: is it the device or the network?
Run through this quickly before touching settings.
- Other devices work, this one doesn’t. Device-side problem. Skip to the device fixes.
- Nothing connects at all. Router, modem, or ISP. Check whether the router’s internet light is solid.
- Connects but says “No Internet.” Wi-Fi is fine; the internet behind it isn’t, or DHCP handed out a bad address. Different problem entirely.
- Works in one room, not another. Coverage, not configuration. You need an access point, not a reset.
- Worked yesterday, stopped today, nothing changed. Something did change — a router firmware update, an ISP-pushed config, or a device OS update. Ask around.
That last one matters more than it sounds. ISP-supplied routers update themselves overnight, and a firmware push that turns on WPA3 or enables band steering will silently break older tablets while every modern phone in the building carries on fine.
The basics that actually fix things
Forget the network and rejoin
This resolves more iPad and iPhone Wi-Fi problems than anything else, because the stored profile — saved password, security type, assigned address — goes stale and the device keeps trying to reuse it.
On iPadOS or iOS: Settings > Wi-Fi, tap the blue circled i next to the network name, tap Forget This Network, confirm. Then reselect the network and type the password fresh.
Type the password rather than pasting it, and watch for the classic offenders — a capital I versus lowercase l, zero versus O, and iOS auto-capitalizing the first character. On a network password, that first-letter capitalization is silently wrong about a third of the time.
Airplane mode toggle
Feels too simple to work. It resets the radio stack and clears a stuck association. Swipe into Control Center, tap the airplane icon, wait ten full seconds, tap it off. Ten seconds, not two — the radios need time to actually power down.
Also check that the Wi-Fi toggle in Control Center is genuinely on. On modern iOS, tapping the Wi-Fi button in Control Center only disconnects from the current network temporarily; it reconnects on its own later, which confuses people into thinking Wi-Fi was off when it wasn’t. The authoritative switch is in Settings.
Restart the router properly
Unplug it from power. Wait a full 30 seconds. Plug it back in. Wait two to three minutes for it to fully boot before testing.
The 30 seconds isn’t superstition — capacitors hold charge and a two-second cycle often doesn’t clear RAM. If you have a separate modem, power off both, bring the modem up first and let it sync completely, then bring up the router.
Don’t use a reset button. That’s a factory reset, and it will wipe your SSID, password, port forwards, and static assignments. Power cycle only.
Reset Network Settings
When forgetting the network doesn’t do it, this is the next escalation. Settings > General > Transfer or Reset iPad > Reset > Reset Network Settings.
Know what it wipes before you run it: every saved Wi-Fi network and password on the device, VPN configurations, cellular APN settings, and paired Bluetooth devices. It does not touch photos, apps, messages, or documents. But if that iPad holds the only copy of a Wi-Fi password for a network you can’t easily look up, get that password first.
Before you reset: on an iPad signed into iCloud Keychain, you can read a saved password at Settings > Wi-Fi, tap the i next to the connected network, tap the hidden Password field and authenticate with Face ID or your passcode. Do that for any network you’ll need to rejoin.
The older-device problem
This is the big one for “old iPad won’t connect to Wi-Fi,” and it’s almost always the router’s fault rather than the tablet’s.
WPA3 locks out old radios
Routers sold in the last few years increasingly ship with WPA3 enabled by default, and some default to WPA3-only rather than a mixed mode. Devices with Wi-Fi chipsets predating roughly 2019 don’t speak WPA3. They see the network, try to authenticate, and fail — usually with “Incorrect password” or an endless spinner, which sends everyone down the password rabbit hole for no reason.
The fix is on the router. Log into its admin page (typically 192.168.1.1 or 192.168.0.1), find the wireless security setting, and change it from WPA3-Personal to WPA2/WPA3 mixed or WPA2-Personal. Mixed mode lets new devices use WPA3 while old ones fall back to WPA2. That’s the setting you want in almost every small office.
5 GHz-only and band steering
Mesh systems and newer routers often broadcast one SSID across 2.4 GHz, 5 GHz, and sometimes 6 GHz, deciding for the client which band to use. That’s called band steering, and it mostly works — except with older clients that only have a 2.4 GHz radio, or ones that negotiate badly and end up refusing to associate at all.
The reliable fix: create a separate 2.4 GHz SSID. Name it something obvious like OfficeWiFi-24. Most router admin panels have a “split bands” or “separate SSID for 2.4 GHz” option under wireless settings. Point the legacy devices at that network and leave everything else on the main one.
The added benefit: 2.4 GHz travels further through walls. Your warehouse scanner or back-office tablet often works better there anyway.
Channel width and legacy mode
Two more router-side settings that break old clients. If 2.4 GHz channel width is set to 40 MHz, some legacy devices choke — set it to 20 MHz. And if the wireless mode is restricted to “N only” or “AX only,” older b/g clients can’t join. Set mode to mixed or “b/g/n.”
Private Wi-Fi Address vs. MAC filtering
Apple devices generate a random MAC address for each network they join. Android does the same thing. It’s a privacy feature and it’s on by default.
It also completely breaks MAC address filtering, which plenty of small offices still use as an access control. The device presents an address your router has never seen, gets rejected, and you get a support ticket. Worse, iOS periodically rotates that address — so a device that was working can stop working weeks later with no apparent trigger.
To turn it off for one network: Settings > Wi-Fi, tap the i next to the network, and set Private Wi-Fi Address to Off (on newer iOS this is a three-way menu — choose Off). Then read the real MAC from Settings > General > About > Wi-Fi Address and add it to the router’s allow list.
The wider point for a business: MAC filtering is not meaningful security. Addresses are trivially spoofed and visible in the clear to anyone listening. All it reliably does is generate helpdesk work. A strong WPA2/WPA3 passphrase, or proper 802.1X if you need per-user control, does the actual job.
DHCP pool exhaustion
Classic small-office failure and one people almost never guess. Consumer routers often default to a DHCP pool of about 50 addresses — say 192.168.1.100 through 192.168.1.149 — with a 24-hour lease.
Count what’s actually on your network: 12 laptops, 12 phones, a handful of personal devices, printers, a couple of tablets, thermostats, cameras, a smart TV in the conference room, and guests cycling through. Each takes an address and holds it for a full day even after leaving. You hit 50 faster than expected.
The symptom is distinctive: the device connects, authenticates fine, then shows a self-assigned address starting with 169.254, or just spins on “Obtaining IP address.” Devices already connected stay fine. New arrivals can’t join.
Fix it in the router’s LAN or DHCP settings — widen the pool to something like .100 through .240, and shorten the lease time to 4 or 8 hours so addresses recycle. If you’re above 40 or so devices on a consumer router, that’s also a signal you’ve outgrown it.
Two odd ones worth knowing
Captive portals that never appear
Hotel, airport, and guest networks put a login page in front of internet access. The device connects, the page is supposed to pop up, and often doesn’t — so you’re on Wi-Fi with no internet and no obvious way forward.
Force it: open Safari and go to http://neverssl.com or http://captive.apple.com. Plain HTTP, not HTTPS — the redirect can’t intercept an encrypted connection, which is exactly why the portal never showed. If it still doesn’t appear, disable Private Wi-Fi Address for that network and rejoin; portals track sessions by MAC and randomization confuses them.
Wrong date and time
This one bites devices that sat in a drawer with a dead battery. Certificate validation checks whether the certificate is valid for the current date. If the device thinks it’s January 2016, every certificate on the internet looks invalid, and any network using certificate-based authentication — or any HTTPS site — fails.
Check Settings > General > Date & Time. Turn on Set Automatically. If it can’t sync because it has no network, set the date manually first, then connect.
Symptom to cause to fix
| What you see | Likely cause | What to do |
|---|---|---|
| “Incorrect password” but the password is right | WPA3-only network, older client | Switch router to WPA2/WPA3 mixed mode |
| Network name doesn’t appear at all | 5 GHz-only SSID, or hidden SSID | Broadcast a separate 2.4 GHz SSID; or join manually via Other |
| Stuck on “Obtaining IP address” or gets a 169.254 address | DHCP pool full | Widen the DHCP range, shorten lease to 4–8 hours |
| Connected, but “No Internet Connection” | WAN down, DNS failure, or captive portal pending | Check router WAN light; browse to http://neverssl.com |
| Was working, quietly stopped weeks later | MAC randomization rotated on a filtered network | Disable Private Wi-Fi Address, allow-list the real MAC — or drop MAC filtering |
| Drops constantly, reconnects, drops again | Channel interference or weak signal at the edge of coverage | Set 2.4 GHz to channel 1, 6, or 11; add an access point |
| Every site shows a certificate error | Device clock is wrong | Settings > General > Date & Time > Set Automatically |
| Only this one device fails, everything else fine | Corrupt stored network profile | Forget network, rejoin; then Reset Network Settings |
| Works near the router, dies down the hall | Coverage gap | Add a wired access point — not a repeater, which halves throughput |
The business angle: separate your networks
While you’re in the router anyway, fix something more important than a single tablet.
In most small offices, everything shares one flat network — the point-of-sale terminal, the file server, the security cameras, the office printer, staff laptops, staff personal phones, and whatever a guest connected to last Tuesday. Any compromised device on that network can see and reach every other one. Ransomware spreads laterally precisely because of this.
Three networks is the practical target, and any decent business router or mesh system supports it:
- Business. Company-owned computers, the server, the POS. Strong passphrase, not written on the whiteboard, changed when someone leaves.
- Guest. Customers and visitors. Isolated from everything else, with client isolation turned on so guests can’t see each other either. Rotate the password periodically.
- Devices. Cameras, thermostats, smart TVs, printers, anything embedded. These are the least patched things you own and the most common foothold. Keep them off the business network.
Staff personal phones belong on guest, not business. That’s not distrust — it’s that you don’t control what’s installed on them, and the business network is where your customer data lives.
Setup on most routers takes about twenty minutes: enable the guest network, enable AP isolation on it, then either use a second guest SSID or a VLAN for the device network. If you’re running an actual POS handling card payments, PCI DSS effectively requires this separation anyway.
Common questions
Why does my iPad connect but say “No Internet Connection”?
The Wi-Fi link is working — the problem is past the router. Either the internet circuit is down, DNS isn’t resolving, a captive portal is waiting for a login, or DHCP handed the device a bad configuration. Check whether other devices have internet. If they do, forget and rejoin on the iPad; if none do, restart the modem and call the ISP.
Does Reset Network Settings delete my photos or apps?
No. It only clears network configuration — saved Wi-Fi networks and passwords, VPN profiles, cellular APN settings, and Bluetooth pairings. Your photos, apps, messages, notes, and documents are untouched. The one real cost is losing every stored Wi-Fi password on that device, so retrieve any you can’t look up elsewhere first.
My old iPad stopped connecting after we got a new router. Is it dead?
Almost certainly not. This is the single most common version of this problem and it’s a router configuration issue nine times out of ten. New routers default to WPA3 and to a single merged SSID across bands. Set security to WPA2/WPA3 mixed, broadcast a separate 2.4 GHz network, and set 2.4 GHz channel width to 20 MHz. That combination brings back the large majority of “dead” old devices.
Should I use a Wi-Fi extender for the dead spot in our back office?
Prefer a wired access point. A repeater or extender receives and retransmits on the same radio, which roughly halves throughput for every device using it, and it introduces a second network name people’s devices cling to at the wrong times. Running an Ethernet cable to a proper access point costs a bit more up front and performs dramatically better. If you truly can’t run cable, a mesh system with a dedicated backhaul band is the next best option.
How many devices can our office router actually handle?
Consumer routers advertise big numbers and deliver comfortable performance for maybe 20 to 30 active devices. Past that you see slowdowns, dropped connections, and DHCP problems even though nothing is technically broken. For a business past about 15 people — where each person carries a laptop and a phone and there are printers, cameras, and a server behind them — a small business-grade router with a separate access point is the right shape. It’s typically a $300-600 hardware change that removes a whole recurring category of complaints.
