When should you use TUN mode? Use cases and checks before you turn it on

What TUN mode is
TUN mode takes over system network requests through a virtual network adapter: network traffic on the device goes into this virtual adapter first, then is handed to the VPN according to your settings. Because the takeover happens at the system level, you don’t have to choose apps one by one, and it covers a wider range than app-level routing.
That cuts both ways. The benefit is that programs that are hard to identify individually, such as command-line tools, development environments and virtual machines, can go through the VPN too. The cost is that more traffic is covered and the effect on your local network is bigger.
How is TUN mode different from a system proxy?
The “system proxy” that many people know is an address you enter in the system settings, and it is up to each app to decide whether to use it. Browsers usually follow this setting, but many command-line tools, background services and games don’t read it, so on the same device some programs go through the proxy and others don’t.
TUN mode doesn’t rely on apps cooperating. Network requests are directed to the virtual adapter at the system level, and the apps themselves don’t need to know a proxy exists. That is also why command lines and development environments suit TUN mode: they don’t read the system proxy but still need to go through the VPN.
Why does TUN mode use more data?
More requests are covered, so naturally more data is used. With TUN mode on, besides the apps you use on purpose, system updates, background syncing and the automatic update checks of various programs may go through the VPN as well. Each of these is small, but together they add up.
Under pay-by-data billing, this is worth keeping in mind. If you need it on for a long time, check the usage in your account now and then so your capacity doesn’t run down faster than expected.
How it differs from app-level routing
| Item | App-level smart routing | TUN mode |
|---|---|---|
| Coverage | Only the apps on the routing list | A wider range of system network requests |
| How you set it up | Choose the apps you need one by one | Once it’s on, the system takes over everything |
| Data use | Easier to control | Usually more than app-level routing |
| Effect on the local network | Smaller | Larger, so confirm what needs a direct connection first |
| Typical uses | Browsers, specific clients | Command line, development environments, virtual machines |
A general rule: if app-level routing can solve the problem, use that first; consider TUN mode only when the routing list can’t cover it.
When TUN mode is a good fit
Command-line tools and development environments
Tools run in a terminal, such as commands that pull dependencies, clone code repositories or call APIs, often can’t be added to the routing list the way ordinary apps can. With TUN mode on, their network requests go through the VPN as well, and you don’t need to configure a proxy for each one.
Tasks involving virtual machines and containers
Network requests from programs inside virtual machines and containers often don’t come from one fixed app, so a routing list can hardly cover them accurately. When these tasks need to go through the VPN as a whole, TUN mode takes less effort.
Software that can’t be added to the routing list
Some software is hard to identify, or starts several subprocesses, so even after you add the main program to the list, some requests still go out over the local network. In this situation, covering it all at once with TUN mode is more reliable than adjusting the routing list over and over.
Short tasks that need to go through the VPN as a whole
One-off environment setup or a complete deployment process, for example, involves many programs and a mix of requests, so configuring them one by one isn’t realistic. These short tasks suit turning TUN mode on temporarily and turning it off when you’re done.
A typical case: pulling dependencies in a terminal
Say you want to clone an overseas code repository in a terminal and then install a batch of dependencies. With app-level routing alone, it is hard to add the terminal and each subprocess it starts to the list one by one. With TUN mode on, the requests from this whole series of commands go through the VPN, and the clone and install can finish in one go. When the task is done, turn TUN mode off and go back to app-level routing; there’s no need to leave it on.
What to check before you turn it on
TUN mode covers more, so it’s worth a minute to confirm the following before you turn it on.
- Confirm whether local services and LAN devices need a direct connection, such as local development services, shared folders and printers;
- Avoid running it alongside other VPN or proxy software that also takes over the network, because the two together often cause network problems;
- Watch your data use: TUN mode covers more requests, so your capacity goes down faster than with app-level routing;
- Turn it off when the task is done, so the device goes back to its normal network state when you no longer need it.
How to troubleshoot problems after turning it on
If a local service or LAN device suddenly can’t be reached after you turn on TUN mode, first ask whether that access used to depend on the local network. If it did, it has been pulled into the VPN along with everything else, and you can turn TUN mode off for now and use app-level routing instead.
If the network becomes slow overall or keeps dropping, check whether other VPN or proxy software is also running on the device, and close one of them before trying again. Several programs taking over the network at once is a common cause of this kind of problem.
If only one app can’t connect while the others work normally, it is likely a setting in that app rather than TUN mode itself. You can go back to app-level routing and deal with only that one app.
If an app reports that the network is unavailable after you turn it on, try turning TUN mode off and on again so the virtual adapter is rebuilt, and confirm that both the client and the system are updated to the latest version. Work from simple to complex: first check for conflicts with other software, then check whether local services have been pulled into the VPN, and only then suspect the configuration itself.
Wrapping up when the task is done
When the task is over, turn TUN mode off as needed so the device returns to its normal network state. After turning it off, you can also check that local services and LAN devices are reachable again. If the next task involves only a few fixed apps, going back to app-level routing uses less data than leaving TUN mode on.
For how to use app-level routing, start with this guide: How to use app-level smart routing.


