Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Gluetun’s firewall is its VPN kill switch: keep it enabled, grant the Gluetun container NET_ADMIN, and route each protected app through Gluetun with network_mode: "service:gluetun". When the VPN connection drops, Gluetun says its firewall blocks traffic from containers sharing its network stack. There is no separate kill-switch toggle in the basic Compose setup.

How Gluetun’s kill switch works

Gluetun’s project documentation calls the feature its firewall and says it effectively acts as a kill switch: if the VPN connection goes down, the firewall blocks traffic. Its default outbound policy allows the traffic needed for the VPN connection, including the VPN interface and the server IP, port, and protocol. Gluetun firewall FAQ

The protection applies to an app only when that app uses Gluetun’s network stack. Merely running Gluetun alongside an application container does not route the app through the VPN or put it behind Gluetun’s firewall.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure a protected app in Docker Compose

This is a minimal configuration shape. Replace the provider, protocol, credentials, and server options with values supported by your VPN provider and Gluetun. The application port shown is only an example; publish it on Gluetun if you need to reach the app’s web interface.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
services:
  gluetun:
    image: qmcgaw/gluetun
    cap_add:
      - NET_ADMIN
    ports:
      - "8080:8080" # Example app web UI; publish here if needed
    environment:
      - VPN_SERVICE_PROVIDER=your_provider
      - VPN_TYPE=wireguard
      # Add provider-specific credentials and server options.

  app:
    image: your-app-image
    network_mode: "service:gluetun"
    depends_on:
      - gluetun

The official Compose example uses Mullvad and WireGuard as illustrative values, not as universal settings. Consult Gluetun’s Docker Compose guide and the instructions for your provider to supply valid credentials and supported settings.

1. Configure the VPN provider and protocol

Set VPN_SERVICE_PROVIDER and VPN_TYPE, then add the provider-specific credentials or keys and any server-selection options required by the provider. A configuration with missing or invalid credentials may not establish a tunnel.

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

2. Give Gluetun network administration capability

Keep NET_ADMIN under Gluetun’s cap_add. Gluetun needs this capability to manage network settings and firewall rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Route each protected app through Gluetun

Set each child service’s network mode to service:gluetun. Check that the app does not also have an independent network path that lets it bypass Gluetun. The Compose guide demonstrates this shared-network arrangement.

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

4. Publish app ports on Gluetun

For a service sharing Gluetun’s network stack, put its Docker port mapping under the Gluetun service, not the child app. For example, the sample mapping 8080:8080 publishes port 8080 on the host and directs it to port 8080 in the shared network namespace. Use the actual port and access requirements of your app.

Allow LAN access without weakening the firewall broadly

By default, a protected container’s traffic is constrained by Gluetun’s firewall. If an app must reach a local device or service, configure FIREWALL_OUTBOUND_SUBNETS with the smallest subnet that meets that need. This setting allows Gluetun and containers sharing its network stack to reach the specified subnet; it is an intentional exception, not a general requirement for the kill switch.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.

Do not add broad private-network ranges by default. Gluetun warns that an allowed outbound subnet overlapping the VPN tunnel’s address range can misroute VPN-related traffic and interfere with port forwarding. Check the configured subnet against the tunnel range. See the project’s firewall options documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Private hostnames and DNS rebinding protection

If a hostname resolves to a private IP address in an allowed subnet, Gluetun’s documentation says you may need to add that hostname to DNS_REBINDING_PROTECTION_EXEMPT_HOSTNAMES. Use the exception for the specific hostname that needs it rather than disabling protection without a clear reason. The option is covered in the firewall FAQ.

Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Distinguish Docker port publishing from VPN port forwarding

These are separate mechanisms with different purposes. A Docker port mapping exposes an application port through the Gluetun container to a host or other network, as configured in Compose. VPN-provider port forwarding gives an external connection a provider-forwarded port through the VPN tunnel; an ordinary Docker mapping does not create that provider-side forwarding.

Goal What to configure Key distinction
Reach a web UI through the Docker host Publish the app’s port under the Gluetun service Docker port mapping; the child shares Gluetun’s network namespace
Accept connections on a port forwarded by the VPN provider Follow the provider-specific Gluetun instructions Provider-side forwarding through the VPN tunnel, separate from Docker publishing

Gluetun documents native VPN-side forwarding for Private Internet Access and ProtonVPN using VPN_PORT_FORWARDING=on. For a designated forwarded port with a provider integration that does not use that native mechanism, the documented option is FIREWALL_VPN_INPUT_PORTS. Check the current port-forwarding guide for the applicable provider path and settings.

Troubleshoot the common setup failures

The app still has internet access outside Gluetun

  • Confirm the app uses network_mode: "service:gluetun".
  • Check for another network path that could bypass Gluetun’s network stack.
  • Verify that Gluetun has NET_ADMIN and that the VPN connection is configured with valid provider settings.

The app’s web interface is unreachable

  • Confirm the port mapping is on the Gluetun service rather than the child app.
  • Check that the host-side and app-side port numbers match the app’s actual configuration.
  • Consider whether the firewall needs an input exception for the intended access path; do not add one unless required.

The app cannot reach a local device

  • Identify the narrowest subnet containing the device or service the app needs.
  • Allow that range with FIREWALL_OUTBOUND_SUBNETS.
  • Check that it does not overlap the VPN tunnel range, and consider DNS rebinding protection if access uses a private hostname.

VPN port forwarding stops working

Check for overlap between FIREWALL_OUTBOUND_SUBNETS and the VPN tunnel range. Then confirm that you configured the provider’s forwarding mechanism, rather than relying only on a Docker port mapping. Gluetun documents these routing and forwarding details in its firewall options and port-forwarding guide.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the documented timing does—and does not—show

Gluetun’s FAQ says firewall setup takes about 15 milliseconds from container start and that setting the firewall rules itself takes 10 milliseconds. The FAQ does not state a publication date for these figures. They are project documentation timing claims, not independent performance tests or measurements of leak-prevention reliability. The documentation does not provide a named statistic for killswitch reliability, leak frequency, or security outcomes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.