Gluetun Features Explained

Gluetun Features Explained

What makes it stand out? Understanding the core Gluetun features helps you get the most from your setup. From the firewall-based kill switch to the built-in proxies, here's what defines the experience.

Built-In Kill Switch

Gluetun configures a firewall so that traffic can only leave through the VPN tunnel. If the connection drops, nothing leaks — everything routed through Gluetun simply waits until the tunnel is restored.

Encryption lock illustrating Gluetun security features

WireGuard & OpenVPN

You choose your protocol with a single variable. WireGuard is modern and fast; OpenVPN is broadly compatible. Gluetun handles the tunnel setup for both.

DNS Over TLS & Filtering

  • Encrypted DNS-over-TLS resolution out of the box.
  • Optional block lists for ads, malware, and trackers.
  • No plaintext DNS leaking outside the tunnel.

Proxies & Port Forwarding

Gluetun ships an HTTP proxy and a Shadowsocks proxy, so apps on your LAN can send traffic through the VPN without joining its container. On supported providers it can also request and expose a forwarded port automatically.

New here? Start with our complete beginner's guide before diving in.

Control Server API

A small HTTP control API lets you check status, read the current public IP, and trigger reconnections programmatically — handy for dashboards and automation. If you're choosing a protocol, our WireGuard vs OpenVPN comparison can help.