Alternatively, push this registry key: HKLM\SOFTWARE\Kerio\VPNClient\Security\BlockTrafficOnDisconnect = 0 (DWORD)
Earlier clients had a documented issue where, during a VPN disconnect, IPv6 traffic would bypass the tunnel and expose the user’s real ISP address. Build 942 introduces a feature, ensuring that all traffic—v4 and v6—stays inside the encrypted tunnel. kerio control vpn client 942