Overview
ProtonVPN is the desktop client for an encrypted tunnel service, and the parts worth caring about are the ones that decide what happens when things go wrong rather than the ones on the front panel. The kill switch blocks all traffic if the tunnel drops rather than silently falling back to the open connection, and a permanent mode keeps that block in place across a reboot until the tunnel is back.
The routing options go past a single hop. Multi-hop sends traffic through two servers in different jurisdictions so neither one sees both ends, split tunnelling lets chosen applications or addresses bypass the tunnel entirely, and there is a mode that routes onward onto an anonymity network without a separate browser. Port forwarding is available for anyone running a peer to peer client behind it.
Protocol handling is the practical part on restrictive networks. The client offers the modern lightweight protocol, the older established one, and an obfuscated transport that presents the connection as ordinary encrypted web traffic when the usual ports are filtered. Servers are listed by country, load and specialisation, with a favourites list and per-profile automatic connection rules.
What it does well
Kill switch
Blocks traffic entirely if the tunnel drops, with a permanent mode that survives reboots until the connection is restored.
Multi-hop routing
Route through two servers in separate jurisdictions so no single hop observes both the source and the destination.
Split tunnelling
Choose applications or addresses that bypass the tunnel, which keeps local devices and banking sites reachable.
Protocol switching
Modern and established tunnelling protocols plus an obfuscated transport for networks that filter the usual ports.
Server selection
Full server list with country, load and specialisation, favourites, and profiles that connect automatically on a chosen network.
Changes in this build
- Connection speeds improved on the modern protocol after a routing change.
- Obfuscated transport reworked for networks that block by traffic shape.
- Split tunnelling now accepts address ranges alongside applications.
- Server list gained sorting by measured latency rather than reported load.
- Fixed a kill switch state that persisted after a clean disconnect.
What is in the package
- Desktop client installer, 64-bit
- Tunnel adapter drivers
- Kill switch and split tunnelling modules
- Server list with automatic profiles
- Multilingual interface files, 22 languages
System requirements
| Processor | Any x64 processor |
| Memory | 2 GB minimum |
| Graphics | Not applicable |
| Storage | 400 MB free |
| Display | 1024 x 768 minimum |
| Network | Any internet connection |
Installation
- Extract the archive to a local folder.
- Run setup and allow the tunnel adapter drivers to install.
- Apply the included configuration step before the first launch.
- Turn on the kill switch before connecting for the first time.
- Test the connection, then check that traffic stops when you disconnect abruptly.
Before you start
Permanent kill switch mode blocks the connection when the client is not running, which is the point but surprises people.
The obfuscated transport is slower, use it only where the standard protocols are filtered.
Split tunnelling rules are evaluated per application path, moving an executable breaks its rule.
Questions about this title
Is there a kill switch?
Yes, with a permanent mode that holds the block across reboots.
Can I route through two servers?
Yes, multi-hop sends traffic through two in different jurisdictions.
Does it work on restrictive networks?
Usually, using the obfuscated transport when the standard ports are filtered.
Can some applications skip the tunnel?
Yes, split tunnelling handles that by application or address.
About this listing
This entry was checked on a clean install of Windows 10 / 11 (64-bit) before it was published, and it is rechecked whenever the package is rebuilt. The figures on this page come from the site index rather than from the publisher, so the download count is what people here have actually pulled.
If a mirror stops answering, use the contact form and it gets replaced. Reports about a specific title are handled faster than general messages because they name the file, the mirror and the point at which the transfer stopped.
Requests for a different version, a different language build or an older release go on the requests page. Older versions of a title are usually still held even when only the current one is listed.