What Is a VPN Kill Switch? Tunnels and Providers Explained

A VPN kill switch, a VPN tunnel, and a VPN provider are three parts of the same system. Here is what each one does, what happens when the tunnel drops, and how the kill switch works when the VPN runs on your router instead of an app.

Updated on

As an Amazon Associate, ModemGuides.com earns from qualifying purchases. This article contains an affiliate link.

Short answer: A VPN tunnel is the encrypted connection between your device (or router) and the VPN company's server. A VPN kill switch is a safety feature that blocks all internet traffic the instant that tunnel drops, so nothing leaks out over your normal connection. A VPN provider is the company that runs the servers on the other end of the tunnel and sells you the subscription. Together they decide whether your VPN protects you all the time or only most of the time.

Key Takeaways

  • The tunnel is the protection. The kill switch is the backup plan for the seconds or minutes when the tunnel is down.
  • On a phone or laptop the kill switch lives in the VPN app. On a router it lives in the router's firmware, and it covers every device in the house at once.
  • The provider you choose matters more on a router than in an app, because not every provider hands out the configuration files a router needs.

What Is a VPN Tunnel?

When you connect to a VPN, your device and the VPN server agree on an encryption key and open a private channel between them. Everything you send goes into that channel scrambled, travels across your internet provider's network in scrambled form, and is unscrambled only when it reaches the VPN server. The server then sends it on to the website or app you wanted. Replies come back the same way in reverse.

That private channel is the tunnel. The name is a good one: your traffic still crosses the same wires and the same ISP network it always did, but from the outside nobody can see what is inside. Your ISP sees a steady stream of encrypted data going to one address (the VPN server). The websites you visit see the VPN server's address instead of your home address.

A tunnel has two ends. One end is whatever is running the VPN software: a phone app, a laptop app, or a router with a built-in VPN client. The other end is a server owned by the provider. The protocol (WireGuard or OpenVPN on most home gear) is the set of rules both ends use to build and maintain the tunnel. If you want the differences between those two protocols and how they perform on router hardware, that is covered in our hardware VPN router guide.

Why tunnels drop

Tunnels are not permanent. They go down when:

  • Your WiFi or cellular connection blips, even for a second
  • Your laptop wakes from sleep and reconnects to the network
  • The VPN server you were on gets overloaded or goes offline for maintenance
  • Your ISP has a brief outage and your modem re-syncs
  • The VPN app crashes or updates in the background

Most of the time the software reconnects on its own within a few seconds. The problem is what happens during those few seconds, and that is the whole reason a kill switch exists.

What Is a VPN Kill Switch?

A VPN kill switch is a rule that says: if the tunnel is not up, no traffic leaves this device at all. When the tunnel drops, the kill switch blocks your internet connection completely until the tunnel is rebuilt. Without it, your device falls back to its normal unprotected connection the moment the VPN disconnects, and it does so silently. Your email app checks for mail, your browser reloads a tab, your TV pings its update server, and all of it goes out over your regular connection with your home address attached.

Think of the tunnel as a sealed mail bag and the kill switch as the rule that the mail truck does not leave the building unless the bag is sealed. If the bag is open, the truck waits. It is inconvenient for a moment, but nothing goes out exposed.

App-level vs. system-level kill switches

Most VPN apps offer two versions of the feature, though the names vary by provider:

  • App-level (standard) kill switch: Blocks internet only while the VPN app is running and the tunnel unexpectedly fails. If you close the app on purpose, your normal connection comes back.
  • System-level (always-on or permanent) kill switch: Blocks internet any time the VPN is not connected, including before the app launches after a reboot and after you quit the app. Nothing gets online unless the tunnel is up.

The first is the sensible default for most people. The second is for anyone who never wants a single packet leaving without the VPN, and it is the setting that produces the most "why is my internet not working" support tickets, because people forget it is on.

The kill switch on a router

When the VPN client runs on your router, the kill switch runs there too, and it protects every device on the network at once. That includes smart TVs, streaming sticks, game consoles, and anything else that cannot run a VPN app of its own.

The feature goes by different names. On GL.iNet routers, older firmware calls it Block Non-VPN Traffic. Starting with firmware 4.8, GL.iNet splits it into a Tunnel Kill Switch that is switched on by default whenever a VPN tunnel is active, and an optional Enhanced Kill Switch in Policy Mode that decides what happens to devices you have excluded from the VPN. ASUS, TP-Link, and other brands with built-in VPN clients usually label it "kill switch" or "block internet access if VPN disconnects" somewhere in the VPN client settings.

One difference from an app kill switch is worth knowing before you turn it on. Some router implementations block traffic whenever the VPN is not connected, including when you switched the VPN off yourself. That is stricter than most app kill switches. If your whole house loses internet after you disable the router's VPN, this is why. Turn the kill switch off first, then the VPN, or leave the tunnel up and use split routing instead.

Kill switch trade-offs

A kill switch is a deliberate choice to prefer no internet over unprotected internet. That is the right call for the traffic you bought the VPN for. It can be the wrong call for the rest of the house:

  • A dropped tunnel takes the smart TV, the video doorbell, and the kids' homework offline along with your laptop.
  • Some streaming services block traffic from VPN servers. If your TV is behind a router-level tunnel with the kill switch on, it may have no working path at all.
  • Work laptops that already run a corporate VPN can misbehave inside a second tunnel.

The usual fix is split routing (GL.iNet calls it Policy Mode): send the devices or destinations you care about through the tunnel, let everything else use the normal connection, and apply the kill switch only to the tunneled group. Our GL.iNet Flint 2 coverage walks through that setup on the router we run in-house.

What Is a VPN Provider?

The VPN provider is the company that owns or rents the servers at the far end of your tunnel. When you pay for a VPN, you are paying for access to those servers, the apps that connect to them, and the company's promise about what it does (or does not do) with your traffic once it arrives. Proton VPN, Mullvad, NordVPN, Surfshark, and ExpressVPN are all providers. WireGuard and OpenVPN are not providers; they are the protocols the providers use.

This distinction gets muddled because the provider's app and the provider's service arrive as one package. The app is just a convenience layer. The service is the servers, the encryption keys, and the policy. A router can use the service without ever touching the app, and that is exactly where provider choice starts to matter.

What to look for when your router is the client

Every provider comparison online is written for people picking a phone app. If the VPN is going to live on your router, the checklist is different:

  • Downloadable configuration files. A router cannot run the provider's app, so it needs a config file (a small text file with the server address and keys) to build the tunnel. Every serious provider offers OpenVPN files. Fewer offer WireGuard files, and WireGuard is the one you want on a router because it runs several times faster on the same hardware. Proton VPN and Mullvad let you generate WireGuard configs from your account page. NordVPN, as of this writing, offers OpenVPN files for routers and keeps its WireGuard-based NordLynx connections inside its own apps, so a NordVPN router setup means OpenVPN and lower speeds. Check this before you buy a subscription, not after.
  • Device limits. A router counts as one device on your plan no matter how many things sit behind it. That makes router-level VPN the cheapest way to cover a large household.
  • Server choice and load. A router will not hop between servers the way an app does. Pick a provider with plenty of servers near you so you can choose a lightly loaded one and leave it.
  • Port forwarding, if you host anything. Most providers do not offer it. If you run a game server, a camera system, or anything else that needs to accept incoming connections through the tunnel, see our CGNAT and port forwarding guide for which providers still support it.
  • Independent no-logs audits and jurisdiction. The provider can see everything your ISP used to see. Choose one that has had its no-logs claim checked by an outside auditor and that is based somewhere without data-retention laws forcing it to keep records.

Two things a provider cannot do for you: the kill switch on a router comes from the router's firmware, not from the provider, and no provider can hide what software running on your own devices reports back to its maker from inside the tunnel. That second point is the subject of our Microsoft GDID article, and it is worth reading before you assume a VPN makes you anonymous.

App or Router: Which One Needs the Kill Switch?

If you only use a VPN on a laptop at coffee shops, the app's kill switch is enough. Turn it on and forget about it.

If you want the VPN to cover the whole house, put the client on the router, use split routing so streaming devices keep working, and enable the router's kill switch for the tunneled group. That gives you an always-on tunnel for the devices that matter with no app to install and no per-device limit to hit. The hardware side of that decision, including which routers have a VPN client fast enough to be worth using, is in the hardware VPN router guide.

And if the goal is protection on hotel or public WiFi while traveling, a travel router with a built-in VPN client does both jobs at once: it puts your devices on a private network and pushes everything through the tunnel. The GL.iNet Beryl AX is the model we stock for that. For the whole-home version, the GL.iNet Flint 2 on Amazon is the router the rest of this article was written on. That is an affiliate link; ModemGuides.com earns a commission on qualifying purchases at no extra cost to you.

Frequently Asked Questions

Does a VPN kill switch slow down my internet?

No. The kill switch does nothing while the tunnel is up. It only acts when the tunnel drops, and then it blocks traffic rather than slowing it. Any speed loss you notice comes from the tunnel itself, not the switch.

Why does my internet stop working when I turn off the VPN?

Almost always because a system-level or router-level kill switch is still on. Disable the kill switch first, then the VPN. On GL.iNet routers with firmware 4.8 or later, the Tunnel Kill Switch is on by default whenever a tunnel is active, so this catches a lot of first-time users.

Is a kill switch the same as an always-on VPN?

Not quite. Always-on means the VPN tries to connect automatically whenever the device is online. A kill switch means traffic is blocked whenever the VPN is not connected. Most apps offer both, and using them together is what gives you a connection that is never unprotected.

Does a kill switch stop DNS leaks?

It stops the kind of leak that happens when the tunnel drops and your device falls back to your ISP's DNS servers. It does not fix a misconfigured tunnel that sends DNS lookups outside the VPN while connected. For that, make sure the VPN's own DNS servers are set inside the config file, and see our DNS servers guide for how to check.

Can I use a free VPN provider on a router?

Rarely, and you should not want to. Most free tiers do not provide config files, cap your speed, or make money by logging traffic. Proton VPN's free tier is the notable exception in that it is run by a paid provider with an audited policy, but router configs require a paid plan.

What does "VPN tunnel disconnected" mean?

The encrypted connection between your device or router and the VPN server has closed. Usually the software reconnects on its own. If it does not, try a different server, check that your underlying internet connection is up, and confirm the config file has not expired (some providers issue keys that need to be regenerated periodically).

Does the router kill switch cover devices I excluded from the VPN?

It depends on the firmware. On GL.iNet 4.8 and later, the Tunnel Kill Switch applies only to devices routed through that tunnel; excluded devices keep normal internet unless you also enable the Enhanced Kill Switch. On some older firmware and other brands, the switch is global and takes excluded devices offline too. Test it once with the VPN deliberately turned off before you rely on it.

USA-Based Modem & Router Technical Support Expert

Our entirely USA-based team of technicians each have over a decade of experience in assisting with installing modems and routers. We are so excited that you chose us to help you stop paying equipment rental fees to the mega-corporations that supply us with internet service.

Updated on

Leave a comment

Please note, comments need to be approved before they are published.