Kill switch not working when connected Via drop in gateway

Hi,

I am using SFT-1200 router and my firmware version is - 4.7.2

I have setup wiregaurd nord vpn, and the Block non VPN traffic is on. This works perfectly fine when I connect to the routers own wifi. When I disconnect from VPN the internet stops working which is as expected.

Now when I use drop in gateway - selected device only option - I have set the wifi settings correctly with proper dns server and gateway which points to the drop in gateway. vpn connection works, checked the server ip and it is the Ip from vpn but when I stop the vpn , I can now still access the internet and now server ip is exposed and my original IP is shown. Ideally the internet should be blocked when VPN is turned off.

Regards,

Dalton

Hi

The Kill Switch is implemented by adjusting firewall zones.

In the default router mode, when enabled, it only allows LAN → VPN traffic forwarding while blocking LAN → WAN forwarding.
This prevents LAN-to-WAN traffic when the VPN tunnel is disconnected.

In Drop-in Gateway mode, all traffic srouce from the WAN port, making it impossible to block WAN to WAN traffic.
In this scenario, the Kill Switch will not function.

Thank you for the reply, in that case, I think it should be clearly mentioned as a note, because we have the functionality of block non vpn and most users will use it assuming it works. There should be a note saying that this feature does not work in drop in gateway mode.

We have indeed identified this use case and addressed it in the 4.8.x release.
However, this version has not yet been released for the SFT1200, and it may take some time.
(No estimated release date is currently available to share.)