Ir para o conteúdo
FortiSafe VPN

Kill switch: what it is and how a VPN kill switch works

FortiSafe team ·

A kill switch is the feature that blocks your device's internet access when the VPN isn't connected, so nothing leaves outside the tunnel without you noticing. On Android, the option comes from the system itself; on Windows, iPhone and Mac, it depends on the VPN app. In the FortiSafe apps, the kill switch is in development.

What it's for

A VPN connection can drop, for example when your device switches networks, loses signal or the server goes down. Without a kill switch, apps keep using the internet over the regular network, outside the tunnel, and you're not always told.

The kill switch closes that gap: while the VPN isn't connected, traffic that wouldn't go through the tunnel is blocked.

How it works

The kill switch relies on system or firewall rules. In the official WireGuard app for Windows, for example, the rules let through the tunnel's own packets, the configured DNS server and the local traffic the network needs, and block everything else.

No kill switch blocks absolutely everything: each system leaves out what the network needs to work, such as DHCP, which gives the device its address on the local network.

Where kill switches exist today

SystemWhat's availableWhat's left out
Android In the VPN options in Settings, always-on VPN (since Android 7.0) and the Block connections without VPN option, when the VPN app supports it. With it on, the system blocks all traffic that doesn't use the VPN. If the VPN app uses a list of allowed or disallowed apps, apps outside the list lose their connection. The app may also not support the feature, in which case the options are disabled.
Windows, in the official WireGuard app A firewall-based kill switch when the tunnel has a single server and sends all traffic through it. The tunnel editor has a checkbox that turns it on and off. The tunnel's own packets, the configured DNS, the machine's internal traffic (loopback), DHCP and, for IPv6, NDP.
iPhone and Mac It depends on the app. Apple gives VPN apps an option that sends most traffic through the tunnel, available since iOS 14 and macOS 10.15. Traffic that keeps the device connected to the local network, such as DHCP; the Wi-Fi login portal; some cellular-only services, such as VoLTE; and communication with companion devices, such as Apple Watch.

How to turn it on in Android

  • Open your device's Settings app and tap Network & internet, VPN. If you can't find it, search for "VPN".
  • Tap Settings next to the VPN you use.
  • Turn on Always-on VPN and, if it's there, Block connections without VPN.
  • Android warns that you won't have internet until the VPN connects. Confirm to continue.
  • If the VPN drops or can't connect, you'll see a notification that can't be dismissed. It goes away when the VPN reconnects or when you turn the option off.
  • The path and names may differ depending on your device's manufacturer.

What changes day to day

With the kill switch on, if the VPN isn't connected, you have no internet. That's expected, not a fault: Android warns you when you turn the option on.

To use the internet without the VPN, you need to turn the kill switch off first.

What about FortiSafe?

The kill switch in the FortiSafe apps is in development and isn't available yet.

FortiSafe uses WireGuard. How it works inside is covered in our article on the protocol.

Sources

Pages checked on 14 September 2026.