Applicability Note
This article applies when one owner's laptop cannot connect to the internet onboard while other devices may or may not be working.
Applicability depends on yacht Wi-Fi design, owner network policy, device management, VPN software, captive portals, DNS/DHCP design, firewall policy, WAN state, and whether the owner device is personal, business-managed, or family-office managed.
What You Should Learn
- Define whether the problem is the laptop, Wi-Fi, local addressing, DNS, firewall, or WAN.
- Avoid rebooting the whole network before collecting evidence.
- Compare the owner's laptop with a known-good device on the same SSID.
- Escalate with facts: IP, gateway, DNS, SSID, signal, and WAN state.
The First Rule
Do not start by restarting the firewall, Starlink, VSAT, or access points. The owner's laptop may be the only affected device. A broad reset can interrupt guests and remove the evidence needed to solve the fault.
Start narrow, then widen.
Step 1: Confirm The Scope
Ask:
- Is only the owner's laptop affected?
- Can the owner's phone connect on the same SSID?
- Can another laptop connect in the same location?
- Is the issue Wi-Fi association, no internet, slow internet, VPN failure, or one website?
- Did the laptop work ashore, in another cabin, or yesterday?
If other devices work on the same SSID, focus on the laptop. If all devices fail on that SSID, focus on Wi-Fi, VLAN, DHCP, DNS, firewall, or WAN policy.
Step 2: Check Wi-Fi Basics
Confirm:
- correct SSID,
- correct password or certificate,
- signal strength,
- cabin or deck location,
- 2.4/5/6 GHz band behaviour,
- captive portal state,
- MAC randomisation or private Wi-Fi address setting,
- whether the laptop is blocked or quarantined by policy.
If the laptop connects near one access point but not another, suspect RF coverage, roaming, band steering, or access-point configuration.
Step 3: Check Addressing
Record:
- IP address,
- subnet mask or prefix,
- default gateway,
- DNS server,
- Wi-Fi SSID,
- VLAN if visible from the controller,
- lease time.
If the laptop has no valid address, suspect DHCP, VLAN mapping, Wi-Fi policy, or endpoint security. If it has a valid address but wrong gateway or DNS server, suspect DHCP options or the wrong network.
Step 4: Separate DNS From Internet
Test whether the laptop can reach:
- default gateway,
- firewall or router address,
- public IP address where allowed,
- a normal website by name,
- another website by name.
If public IP works but names fail, focus on DNS. If nothing beyond the gateway works, check firewall policy, WAN failover, or laptop VPN/security software.
Step 5: Check Laptop-Specific Causes
Owner and family-office laptops often have security software, VPNs, DNS filtering, proxy settings, device certificates, or managed profiles.
Check:
- corporate VPN forced on,
- proxy configured,
- custom DNS set,
- endpoint firewall blocking new networks,
- date and time incorrect,
- expired certificate,
- browser captive-portal block,
- privacy MAC causing policy mismatch.
Do not remove corporate controls without approval. Capture the evidence and involve the owner's IT support if needed.
Practical Yacht Scenario
The owner's laptop joins the owner SSID but says there is no internet. The owner's phone works. The laptop has a valid IP, gateway, and DNS. It can reach a public IP but cannot open websites. A corporate VPN client is forcing DNS to an office resolver that is unreachable over the yacht network.
The yacht internet is not down. The action is to involve the owner-office IT team or use the approved VPN profile, not reset the yacht WAN edge.
Evidence To Capture
- Time and location.
- SSID and access point if known.
- IP, gateway, DNS, and lease.
- Signal strength or controller client view.
- Gateway, public IP, and DNS test results.
- WAN status from firewall.
- VPN/proxy/security software state.
- Action taken and result.