What Is a VPN Kill Switch?
A plain-English explanation of VPN kill switches, what they do when a tunnel drops, what they do not protect, and why behavior differs by device and VPN client.
Last reviewed: September 1, 2026
Split tunneling lets some traffic use the VPN while other traffic uses the normal network path. That flexibility can be useful, but it also means not every application or destination receives the same VPN protection.
In a full-tunnel design, traffic covered by the VPN profile is routed through the VPN. In a split-tunnel design, rules decide which applications, networks or destinations use the VPN and which continue directly through the local internet connection.
Traffic excluded from the VPN is not protected by the VPN tunnel. It may use the normal public IP and the local network path. That is not necessarily a leak if it is an intentional rule, but users should know which traffic is intentionally outside the tunnel.
If one application works and another does not, or two applications appear to use different public IP addresses, split-routing rules may be involved. Before changing DNS or reinstalling the client, confirm whether traffic is intentionally divided.
A split-tunnel rule says where traffic should go. A kill switch says what should happen when a protected VPN path is unavailable. The two features can interact, but they solve different problems.
Split tunneling can be based on applications, destination networks, IP ranges, local networks, or routing tables. A work VPN may send only corporate subnets through the tunnel, while a consumer client may let the user select applications to include or exclude. These designs produce similar user-visible results but are implemented differently.
Test the public IP from an application that should use the VPN and from one that should not. If local-network access is intentionally preserved, confirm that printers or other local services remain reachable. Document the intended behavior before troubleshooting so an intentional direct route is not mistaken for a leak.
Not necessarily. Traffic outside the tunnel can be intentional. A leak is unintended exposure contrary to the expected configuration.
That depends on the client and routing policy. Some configurations intentionally preserve access to local networks.
It is simpler from a privacy perspective because more traffic follows one protected route, but split tunneling can be useful when compatibility or local access matters.
A plain-English explanation of VPN kill switches, what they do when a tunnel drops, what they do not protect, and why behavior differs by device and VPN client.
Understand DNS, IPv6, IP and WebRTC leaks and how to test them.
Check whether your public IP changes after the VPN connects.
Plain-English explanation of what a VPN protects in everyday use.
Basic Windows VPN troubleshooting when a connection cannot be established.
Readers who want to test these concepts with a VPN client can use the ZBEVPN Download page. For connection-specific problems, start with the Guides & Knowledge Center.