## TL;DR
The kill switch is doing its job: it blocks traffic when the tunnel drops so nothing leaks outside the VPN. If the user needs local network access (printer, LAN), enable the client's split-tunnel or local-LAN exception. If they just need the internet back, reconnect the VPN or disable the kill switch per policy.

## The error
```text
(No internet at all after the VPN disconnected. Client shows kill switch active.)
```

## Steps
1. Explain in one sentence: "The kill switch blocks your internet when the VPN drops so your traffic never goes unprotected." Expected: user understands it is a feature, not a bug.
2. First try: reconnect the VPN. Expected: traffic flows. Most kill-switch blocks clear the moment the tunnel is back.
3. If the user needs a local printer or LAN device: enable the client's "allow local network access" / LAN exception setting. Expected: LAN works while the tunnel protects internet traffic.
4. If policy allows, show the user how to temporarily disable the kill switch for trusted networks. Expected: user can self-serve next time. If policy forbids it, say so plainly and offer the reconnect path.
5. Check why the tunnel dropped in the first place (see the drops playbook). Expected: root cause addressed. The kill switch is the symptom; the drop is the disease.

## When to use
- Total connectivity loss after VPN drop
- Users confused by kill switch behavior

## When not to use
- VPN will not connect at all
- Partial connectivity (some sites work)

## Compatibility
- VPN clients with kill switch features (most enterprise clients)

## Variants
### Kill switch blocks the captive portal
Use the client's portal-bypass if available; otherwise briefly disable per the travel playbook.
### User wants it off permanently
That is a policy decision, not a helpdesk call. Escalate the request; do not disable silently.

## Why it happens
A kill switch is a firewall rule that only allows tunnel traffic. When the tunnel dies, the rule stays, so everything is blocked. It is working as designed; the design just surprises users.

## Edge cases
- Some kill switches persist across reboots; the user must open the client to clear them.
- Document the expected behavior in the VPN FAQ to cut these tickets.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_H82zo0rW0MyCU8EiQlfT6g
