Kill switch
What the kill switch is, how it stops traffic from leaking when the VPN drops unexpectedly, how to turn it on on each platform and how to check that it works.
A kill switch stops your device from reaching the internet outside the tunnel when the VPN connection drops unexpectedly. That way, even during a brief drop, your real IP address and unencrypted traffic stay hidden. In Colitu the kill switch works the way each operating system allows.
| Platform | How it works | Where to turn it on |
|---|---|---|
| Windows | Colitu's own kill switch, on by default | Settings → Connection → Kill switch |
| Android | Android's system settings | Account → Features → Always-on protection |
| iOS | Always-on protection: iOS reconnects the VPN right away if it drops | Account → Features → Always-on protection |
| Linux (beta) | nftables rules, TUN mode only | Settings → Connection → Kill switch |
Windows
On Windows the kill switch is on by default. To check or change it, use Settings → Connection → Kill switch.
- Colitu adds rules through the Windows Filtering Platform, the security layer built into Windows. While they are active, only the VPN core, the Colitu app, loopback, the TUN adapter, your local network (LAN) and DHCP can pass; everything else is blocked.
- In TUN mode the kill switch is active for as long as you are connected; traffic can't leave outside the VPN at all.
- In system proxy mode (the default mode) it engages the moment the tunnel is lost and keeps the internet closed until Colitu reconnects.
- When it engages, the home screen tells you and Colitu reconnects automatically. If you don't want to wait, you can turn the protection off.
- When you press Disconnect yourself, the kill switch doesn't engage and the internet works normally.
- If Colitu crashes, Windows removes the rules by itself, so your internet doesn't stay locked.
Android
On Android the kill switch is provided by Android itself. Colitu takes you to the right screen:
- In Colitu open the Account tab and tap Always-on protection under Features. Android's VPN settings open.
- Tap the settings (gear) icon next to Colitu.
- Turn on Always-on VPN.
- Turn on Block connections without VPN.
From then on no app can reach the internet while Colitu isn't connected. The names and location of these settings can differ slightly between manufacturers; on most phones they are under Settings → Network & internet → VPN. Only one VPN app can be "always on" at a time.
iOS
On iOS turn on Account → Features → Always-on protection. If the VPN drops because the network changed or it was switched off in Control Centre, iOS reconnects it right away.
This uses iOS's on-demand mechanism and brings the VPN back quickly; it is not a classic kill switch that blocks all traffic. Local networks are also kept outside the tunnel on iOS, so you can reach your local devices.
Linux (beta)
On Linux the kill switch works in TUN mode only:
- Under Settings → Connection → Mode choose All traffic (TUN).
- In the same section make sure Kill switch is on. It is on by default but has no effect in proxy mode.
- Make sure the
nftablespackage is installed.
While the kill switch is active and the VPN drops, only the local network, the VPN servers and the Colitu account service stay reachable. The rules are removed automatically when the app exits, even after a crash.
How do I check that it works?
- Connect to Colitu and open the VPN connection test. The IP address and location should show the Colitu server and no leak should appear.
- While connected, turn Wi-Fi or mobile data off for a few seconds and on again.
- Pages should not load until Colitu has reconnected. Once it's back, run the test again; it should show the Colitu server again.
- On Android, also disconnect in Colitu: with Block connections without VPN on, no site should open.
More tests: Connection tests.
Troubleshooting
| Symptom | Fix |
|---|---|
| I closed the window on Windows and have no internet | Colitu may keep running in the tray after you close the window, and the kill switch may be waiting for a reconnect. Open Colitu from the tray icon and reconnect, or disconnect. When Colitu exits completely, Windows removes the rules. |
| "The kill switch couldn't be turned on" on Windows | Close Colitu and start it again as administrator. |
| No internet on Android while Colitu is off | That is exactly what Block connections without VPN does. Connect with Colitu or turn this setting off in Android's VPN settings. |
| I want to use another VPN on Android | First turn off Always-on VPN for Colitu. |
| The kill switch doesn't work on Linux | Make sure you are in TUN mode and the nftables package is installed. |
| No internet on Linux after Colitu closed | Open Colitu again, connect, then disconnect normally. If it continues, restart the computer and write to support. |
| The kill switch engages often | Your connection drops often. See Connection problems. |
Still need help?
Colitu Bot answers in seconds and hands you over to live support if it can't solve it.