← All articles
Guides

VPN for Windows: system proxy, TUN mode and the kill switch

The difference between system proxy and TUN mode, why you want a kill switch and how to check that all Windows traffic goes through the VPN.

October 1, 2026 · 2 min read

On Windows a VPN app can redirect traffic in two different ways, and the choice decides which programs are actually protected. Here is how it works, using Colitu for Windows 10 and 11 as the example.

System proxy mode

In this mode the app starts a local proxy server and registers it in the Windows settings. Browsers and most programs that respect the system proxy send their traffic through it.

  • Pros: lightweight, with almost no effect on speed.
  • Cons: programs that open their own connections (many games, torrent clients, some messengers and tools) skip the proxy and go direct.

TUN mode

Here the app creates a virtual network adapter. Windows sends all IP traffic into it and the app decides what to do with it. Games, UDP and DNS queries all go through the tunnel.

  • Pros: everything is protected, no exceptions.
  • Cons: Windows may ask for confirmation the first time; slightly more load on very old hardware.

The rule is simple: if a program still shows your real address or country while the VPN is on, turn on TUN.

Kill switch

If the VPN connection drops unexpectedly, Windows quietly keeps sending traffic directly. A kill switch prevents that: while it is on, outbound connections outside the tunnel are blocked.

Colitu's kill switch is built on the Windows Filtering Platform, the same mechanism the official WireGuard client uses. The filters live in a dynamic session, so if the app crashes Windows removes them by itself and you are not left without internet. Only the app, the VPN core, the local network and DHCP are allowed.

Installation and verification

  1. Download the installer from the Colitu for Windows page.
  2. If SmartScreen warns about an unknown publisher, first compare the file's SHA-256 with the value on the page. In PowerShell: Get-FileHash .\ColituVPN-Setup-*-x64.exe -Algorithm SHA256.
  3. Run the installer, sign in and click Connect.

The app installs updates by itself, but only if the update manifest's signature (ECDSA P-256) and the file checksum both match.

How to check that it works

  1. Open What is my IP without the VPN and note the address.
  2. Connect and reload: the address and country should change, and the page tells you the address belongs to a Colitu server.
  3. For programs outside the browser, turn on TUN and check again.

Private logs

VPN cores log lines about DNS queries and connections. Colitu for Windows never keeps those lines and masks host names and addresses in the remaining error messages. So even when you send your log to support, you are not sending your browsing history.

The app's code is open: github.com/cyberlexs/colitu-windows.