
Gluetun Features Explained
What makes it stand out? Understanding the core Gluetun features helps you get the most from your setup. From the firewall-based kill switch to the built-in proxies, here's what defines the experience.
Built-In Kill Switch
Gluetun configures a firewall so that traffic can only leave through the VPN tunnel. If the connection drops, nothing leaks — everything routed through Gluetun simply waits until the tunnel is restored.
WireGuard & OpenVPN
You choose your protocol with a single variable. WireGuard is modern and fast; OpenVPN is broadly compatible. Gluetun handles the tunnel setup for both.
DNS Over TLS & Filtering
- Encrypted DNS-over-TLS resolution out of the box.
- Optional block lists for ads, malware, and trackers.
- No plaintext DNS leaking outside the tunnel.
Proxies & Port Forwarding
Gluetun ships an HTTP proxy and a Shadowsocks proxy, so apps on your LAN can send traffic through the VPN without joining its container. On supported providers it can also request and expose a forwarded port automatically.
New here? Start with our complete beginner's guide before diving in.
Control Server API
A small HTTP control API lets you check status, read the current public IP, and trigger reconnections programmatically — handy for dashboards and automation. If you're choosing a protocol, our WireGuard vs OpenVPN comparison can help.