vpn kill switch blocking non-vpn traffic: how to explain and fix
Explains and fixes VPN kill switches blocking all traffic when the VPN drops. Covers what the kill switch does, when to keep it, and how to allow local network access. Use when users report total internet loss after VPN disconnect. Not for tunnel-establishment failures.
TL;DR
The kill switch is doing its job: it blocks traffic when the tunnel drops so nothing leaks outside the VPN. If the user needs local network access (printer, LAN), enable the client's split-tunnel or local-LAN exception. If they just need the internet back, reconnect the VPN or disable the kill switch per policy.
The error
(No internet at all after the VPN disconnected. Client shows kill switch active.)Steps
- Explain in one sentence: "The kill switch blocks your internet when the VPN drops so your traffic never goes unprotected." Expected: user understands it is a feature, not a bug.
- First try: reconnect the VPN. Expected: traffic flows. Most kill-switch blocks clear the moment the tunnel is back.
- If the user needs a local printer or LAN device: enable the client's "allow local network access" / LAN exception setting. Expected: LAN works while the tunnel protects internet traffic.
- If policy allows, show the user how to temporarily disable the kill switch for trusted networks. Expected: user can self-serve next time. If policy forbids it, say so plainly and offer the reconnect path.
- Check why the tunnel dropped in the first place (see the drops playbook). Expected: root cause addressed. The kill switch is the symptom; the drop is the disease.
When to use
- Total connectivity loss after VPN drop
- Users confused by kill switch behavior
When not to use
- VPN will not connect at all
- Partial connectivity (some sites work)
Compatibility
- VPN clients with kill switch features (most enterprise clients)
Variants
Kill switch blocks the captive portal
Use the client's portal-bypass if available; otherwise briefly disable per the travel playbook.
User wants it off permanently
That is a policy decision, not a helpdesk call. Escalate the request; do not disable silently.
Why it happens
A kill switch is a firewall rule that only allows tunnel traffic. When the tunnel dies, the rule stays, so everything is blocked. It is working as designed; the design just surprises users.
Edge cases
- Some kill switches persist across reboots; the user must open the client to clear them.
- Document the expected behavior in the VPN FAQ to cut these tickets.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_H82zo0rW0MyCU8EiQlfT6g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.