Same PC, different Linux login. Install under that user if the client is per-user.

VPN When Switching Linux User: Same PC, New Login

You switched to a different Linux user on a PC you still own. Per-user NetworkManager leftover. Install amd64 or ARM .deb/.rpm from /download under that user. Not a reinstall, live USB, Windows user switch, or macOS user switch.

KloxVPN Team
22 min readPublished 2024-10-13
VPN When Switching Linux User: Same PC, New Login
Same PC, different Linux login. Install under that user if the client is per-user.

You switched to a different Linux user on a PC you still own. New local account after a messy year. A GNOME user you finally created because the installer only made one admin. You logged out of the old login and logged into a new one. The chassis did not leave. You did not wipe the disk. You did not reinstall Ubuntu. Apps on the old home may still sit in that other Applications menu. The new home can look empty even though /usr still has yesterday's packages. Ranked listicles will mash that into a reinstall, a live USB, a Windows user switch, and a macOS user switch until the affiliate cookie expires. This page is narrower. Same human. Same chassis. Different Linux login. Per-user leftover.

This is not VPN After a Linux Reinstall: Same PC, Empty Disk, Matching Package. That URL is empty Linux. Packages gone. tun gone. Matching .deb or .rpm again because the disk forgot the binary. Here Linux is still the Linux you had. You changed who sits in GDM as the signed-in user. A second Linux user is not a reinstall. This is not VPN on a Linux Live USB: Ephemeral Session, Persistence, Matching Arch. That stick is RAM unless you built persistence on purpose. Reboot throws the client away. This article assumes you installed Linux to a disk you kept, then created another login on that disk. If you only booted try-without-installing, stop and read that URL. This is not VPN When Switching Windows User: Same PC, New Login, Per-User Leftover. That plot is AMD64 or ARM64, an .exe, Run as administrator, a TAP or Wintun-class adapter. Here the OS is Linux. The file is a .deb or an .rpm. There is not a SmartScreen sheet. This is not VPN When Switching macOS User: Same Mac, New Login, Per-User Leftover. That URL is a universal .dmg or .pkg and a Network Extension Apple asked you to allow. Here there is no Applications folder and no System Settings VPN toggle that Klox owns. The leftover here is a home directory and whatever NetworkManager stored for that uid.

HTTPS already encrypts the page on most of the sites you actually use. The lock in the browser is real. A VPN still wraps the path from this PC to a server you picked, once a client actually runs under the account you type in. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. It is not a Linux user. It is not GDM. Encrypted Client Hello will not copy the tray icon into the new home. Do not pretend the padlock migrated Klox. Do not pretend Connect is a Unix uid.

KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. This PC still counts as one seat after you sign in again under the account you actually use. Download ships four Linux files: Klox-linux-amd64.deb, Klox-linux-amd64.rpm, Klox-linux-arm.deb, Klox-linux-arm.rpm. Debian-class takes .deb. Fedora and RHEL-class take .rpm. x64 is Intel and AMD. ARM is ARM. Install under that user if the client is per-user. Allow PolicyKit when the desktop asks. Pricing is the live number. The seven-day window is first purchase, not a user-switch coupon. Cookies on this site live at /cookie. I will not invent a city count as a reason the new login is special. I will not invent a portal URL. I will not invent a Flatpak. I will not invent a Snap name we did not ship. I will not invent SOC 2.

I have a bias. Type klox.app/download while logged into the Linux user you now live in. Run uname -m. Pick the architecture that matches. Install with the package manager if this account cannot see the app. Sign into the same Klox email you already paid on. Look at the old Linux user if the tray still sits there. Remove a leftover slot in the live app if it still sits. Do not switch a Linux user you do not own. Count the household on the Family VPN on Five Devices if a phone is also holding a session.

Related reading: KloxVPN on a Linux Desktop: Packages, NetworkManager, CLI and VPN on Linux ARM: Pick the ARM .deb or .rpm, Not AMD64. What is a VPN? and Android VPN setup. iOS VPN setup.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

A second Linux user is not a reinstall and not a live USB

A Linux reinstall of a PC you kept is a different leftover. /usr is empty of Klox. The package database does not remember last year's .deb. First-run GNOME does not remember that you paid for a year. That essay already owns the empty disk. Switching the signed-in Linux user leaves the OS standing. The other home can still have a launcher. The new home can still be missing the client. Farms skip that sentence because the keyword is privacy. Privacy after you meant a new login is a matching package under that user plus a seat, not a screenshot of Fastest server.

A live USB is RAM unless you built persistence. You are not on a stick. You created a named account, or you signed into one that already existed, on hardware you kept. Mixing those in one sentence is how farms sell best VPN for Linux until the cookie expires. A Windows user switch is AMD64 or ARM64 and an .exe. That essay already owns Win32. A macOS user switch is a .dmg or a .pkg and a Network Extension. That essay already owns Apple's volume. This URL is you, alone, moving from one Linux account to another on hardware you kept. The leftover is per-user. The seat is still the machine while Connect is up.

I will not walk packet sniffing. The public Wi-Fi how-to already did. I will not pack your chargers. The travel checklist exists for install-before-you-fly. Here the PC is already on the desk, same Linux, new login. The download page is the next job if this account cannot see the app. The seat is the job after that. The KloxVPN on a Linux Desktop: Packages, NetworkManager, CLI habit still helps once the binary actually runs here: match .deb or .rpm, one owner for the session, WireGuard first. That page assumes you already live in a home that has the client. You are here because this home might not.

Klox is a consumer tunnel to an exit you picked. It is not Ubuntu's user accounts panel. It is not useradd. Ubuntu's add a new user account help page is the vendor novel. I will stay at overview height. I will not paste a 40-click path that rots when GNOME moves Settings, Users. Farms skip that sentence because the keyword is new user. A new Linux user is the distro's product. Installing Klox under that user is ours.

Download, sign in, connect WireGuard, fall back to OpenVPN
Install from klox.app/download. WireGuard first. OpenVPN if UDP is blocked.

    First successful connect

  1. 1Download the app from klox.app/download — not a random APK site.
  2. 2Sign in with the account you paid for.
  3. 3Press WireGuard. Wait for the connected state.
  4. 4If it fails, try OpenVPN. Still failing: note the network (hotel, campus, home) before you write support.
Switching Linux user versus nearby URLs. Not a Klox SLA. Not a script for an account you do not own.
SituationWhat you think happenedWhat actually happenedThis page?
You reinstalled Linux on YOUR PCNew Linux user deleted the diskPackages gone; tun gone; empty OSReinstall article
Linux live USBA stick is a second userRAM session; persistence is the plotLive-USB article
Windows user switch on YOUR PCSame old as a Linux user switch.exe, AMD64 or ARM64, adapterWindows user-switch article
macOS user switch on YOUR MacSame old as a Linux user switch.dmg or .pkg, Network ExtensionmacOS user-switch article
YOU switched Linux user on YOUR PCThe old install followed you automaticallyPer-user old; new home may need the packageYes
System-wide .deb already in /usrSame as a missing clientBinary can survive; this checklist may not applyOnly if this account cannot see the client
Linux user you do not ownA blog ranked privacyStopNo. Do not switch it.

You switched Linux login on a PC you still own. Get the matching .deb or .rpm from /download under that user if the client is per-user. Sign in. Remove the old slot in the live app. Do not switch a Linux user you do not own.

— KloxVPN consumer notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

Ubuntu Help: add a new user account

Proton VPN: Linux download (competitor specimen)

Same chassis, different Linux login

Reinstall is empty Linux. Live USB is RAM. Windows user switch is an .exe. macOS user switch is a listing. This URL is a login you created or signed into on hardware you kept. Do not paste one checklist into all five days.

This is not the Windows leftover and not the Mac leftover

Win32 is SmartScreen and an adapter prompt. macOS is a Network Extension sheet. Linux is PolicyKit, a tun or WireGuard interface, and a home that may still be empty of the tray. Use the matching URL.

Per-user leftover: NetworkManager stayed with the old home

Linux stores a lot of what you think of as the app inside the user profile. Desktop launchers in ~/.local. Tokens in ~/.config. NetworkManager connections the old uid imported by hand. Switch user and those objects stay with the old login. The new desktop can look like first-run GNOME even though the disk still has yesterday. People then decide the VPN vanished. It did not vanish. It stayed with the other account. Look before you download twice so two trays fight.

NetworkManager is the leftover that farms never name. A connection stored under the old user does not automatically appear for the new one. A connection stored as a system connection in /etc/NetworkManager/system-connections can still sit for everyone, including a handmade WireGuard row that is not Klox. Look at nmcli connection show if you already live in a terminal. Look at GNOME Settings, Network, VPN if you do not. If you see a row you typed last year, that row is not our client. Do not Connect it under the new login and then install Klox on top. Two tunnels is how you get none.

I will not invent a per-user Klox dashboard so this article matches a competitor screenshot. Klox is one consumer account you sign into on a machine. Linux users are OS profiles. They have their own homes. They are not extra Klox seats by themselves. They are also not a free extra install if the binary never landed in this profile. Split those two sentences. Farms mash them because the keyword is user.

GNOME Fast User Switching can keep processes alive. You switch to the new account and the old session is still parked. A tunnel started under the first uid can still be up when you land on the new profile, or the other way around, depending on how the helper is scoped. Machine-wide helper versus per-user tray is a client fact. Confirm it. Then write it. If the VPN is per-user, the new login does not inherit the tray. If a privileged interface is still up, the household is still spending a seat. Look at the icon. Do not assume.

Logging out of GNOME is not a Klox disconnect. Closing the session can drop a per-user helper. It can also leave a peer sitting until the handshake dies. Prefer looking in the live app. A leftover row is a corpse, not a second laptop. Remove it there. I will not mint a portal path. A screenshot from a farm is not our admin.

Do not copy files from the old user's Desktop into the new one and call that an install. Shortcuts break. Tokens stay behind. A .conf you scp'd from /home/olduser/.config is still last year's leftover, not a package. The honest path is /download under the account you now type in. Package manager. Sign into the same email. That is boring. Boring is the point.

Fast user switching is not a logout of Klox

The other session can still hold a tunnel. Check the tray on both logins if you can still reach the old one. A switch is not Disconnect. Prefer the button in the app.

Logging out of GNOME is not a Klox disconnect

The OS session died. The account may still show a device row until the handshake dies or you remove it. A Linux logout is not a VPN feature.

Install from /download under the account you actually use

The new profile returns you to a clean Applications menu. Browser bookmarks are gone unless you signed into a browser profile. The old Klox launcher is on the other desktop. Open a browser you trust while you are this user. Type klox.app/download. Do not search Klox VPN linux deb and click the first ad. Ads impersonate download pages. Bookmark download after the first honest visit.

Four files. Klox-linux-amd64.deb and Klox-linux-amd64.rpm for 64-bit Intel and AMD. Klox-linux-arm.deb and Klox-linux-arm.rpm for ARM. Debian, Ubuntu, and cousins take .deb. Fedora, RHEL-class, and cousins take .rpm. The new home forgot which pair you used last year, even if the old home still has the file in Downloads. Look again. Do not grab last year's USB stick with a renamed package because the filename felt lucky. Renaming Klox-linux-amd64.deb to Klox-linux-arm.deb does not change the binary. Do not copy the old user's Downloads folder and run that file as a personality.

uname -m is the boring check. x86_64 means amd64 packages. aarch64 or arm64 means ARM packages. Do this under the new login, not from memory of the other profile's ThinkPad sticker. A laptop that looks like last year's Intel laptop is how people download the wrong file at 23:00. Wrong arch fails to install or fails to launch. That story in full is VPN on Linux ARM: Pick the ARM .deb or .rpm, Not AMD64. Here the user-switch line is: this home forgot the filename. The ARM article owns the picker. I will point. I will not reprint the uname sermon so three URLs compete.

The new Linux user may not be in sudo. That is a real gate. A system package needs root to land in /usr. If this account cannot sudo, you cannot install a .deb from this login until someone who can sudo does it, or until you add this user to the right group the distro way. I will not write a visudo novel. I will tell you not to share the old user's password in a chat because a farm ranked privacy. If you own the PC, fix sudoers the way you already trust. Then install. Then launch. Sign into the same email you already paid on. A second Klox account is how you lose the year you already bought and then hit a seat error on the old login you forgot.

I will not invent a Flatpak because a new Ubuntu user would have preferred one. I will not invent a Snap. I will not write a curl | bash installer. We did not ship one. Checksum theater: download from klox.app/download, not a mirror a stranger pasted in a forum. If your distro's browser quarantine complains, that is the browser. pkexec or sudo the way you already do. A Drive folder labeled linux vpn latest is still a different product under a fresh home. Empty Applications is not a reason to trust a random archive.

If the old Linux user still has the client and you can still log into it, you can leave the system package sitting. Do not leave two signed-in trays on one chassis unless you like support tickets that start with I switched user and nothing works. One honest launch under the account you live in. Then clean the leftover on the account you left.

WireGuard versus OpenVPN
Klox ships four protocols: WireGuard by default, OpenVPN when UDP fails.

uname -m under this user, then the matching file

x86_64: amd64. aarch64 or arm64: ARM. Do this on the new login, not from a note you wrote last year. Compatibility mode does not exist. qemu-user is not a support plan. Renaming the file does not fix the arch.

A forum package is still a different product under a new profile

A fresh Linux user is not a reason to trust a Mega link. Type the URL. If the filename looks like a codec pack or a VPN booster, you left the path. Remove that first.

If the client is per-user, the other login does not inherit the tray

Some Linux installs land in /usr and show up for every local user. Some land in the profile and do not. Klox's consumer Linux client is a .deb or .rpm from /download. After a system install, another user on the same PC can often launch it from the menu. After a per-user leftover, they often cannot. Look. If this account has no launcher and no tray, install from /download under this account if you have sudo, or launch the system binary if it is already in /usr. If this account already has the tray, skip the second copy. Two copies is how Connect looks haunted.

I will not invent a /usr versus ~/.local picker as a consumer protocol. The Download page does not offer that as a toggle. The practical test is: logged into this Linux user, can you open Klox? Yes: sign in, allow PolicyKit if asked, look at the seat. No: type klox.app/download, matching arch, matching .deb or .rpm, package manager. Do not export a tar of the old user's .config. Do not rsync a home because a forum said roaming was privacy. Homedir copy is the distro's noun. It is not our installer.

A Linux user you just created is still a Unix uid. It is not a Klox SKU. Logging into GDM does not sign you into Klox. Signing into Klox does not create a Linux user. Keep those buttons apart. People mash them because both say account. One is the OS. One is the tunnel you paid for.

Renaming a user with usermod -l can keep the same home if you also moved the folder. That is the distro converting the login, not creating a second human. If you still see the same desktop, the same launchers, and the same tray, this checklist may be the wrong URL. You already have the client. Sign in if the token died. Do not download a second copy so two trays fight. If you created a brand-new user and left the old one sitting, you are on this page. Two homes. Two Applications menus. Maybe one /usr. Look before you assume the hop followed you.

Do not copy the .desktop file from the other home. A launcher that points at a path the new user cannot read is a blank icon and a ticket. The package writes the right files under /usr/share/applications when it is a system install. Your drag-and-drop does not. I have watched people duplicate a .desktop, decide VPNs are broken, and then install a forum archive. The shortcut was the whole bug.

KDE, Cosmic, and a tiling window manager you compiled do not change the leftover. They change whether a tray icon appears. If the tray is missing after a fresh Plasma user, the tunnel can still be up if you launched the window. Look at the app window. Do not reconnect five times because the glyph vanished. That is how you race handshakes on a login you just made.

/usr versus ~/.config is a look, not a slogan

If the menu under this user already launches Klox, you are done with the binary. If it does not, install from /download here. Do not guess from the other profile's wallpaper.

Do not copy the .desktop file from the other home

A launcher is not an install. Tokens stay in the other .config. Type the URL. Install the matching package under this login if the system copy is missing.

This PC is still one of five seats, not two because you have two Linux users

Timeout is the boring failure. You switched Linux user. You did not disconnect first. The account still shows this laptop for a while. You install under the new login, you connect, and you are at five, or you think you were robbed of a slot. You were not robbed. You left a corpse. Remove it in the live app. I will not invent a web portal URL for that tap. Confirm the client you already signed into. If the row is gone on its own, good. If it sits, disconnect that device from a logged-in client. A label is not a logout. Kick is a logout of that seat. It is still not a second PC. It is still not a reinstall. The chassis is the same radio wearing two Unix names.

Two Linux accounts are not two Klox seats by themselves. A seat is a live handshake. If the tunnel stays up across Fast User Switching, the household still spent one seat. If the tunnel drops when the first person logs out, the next login has to Connect again. Look at the app. Do not assume. I will not invent a per-user Klox dashboard so this article matches a competitor screenshot. We did not ship that screen on the desktop app.

I will not print a minutes-and-seconds figure for when a dead peer drops. Networks fail closed, fail open, retry. Prefer in-app disconnect before a user switch you plan, so you are not guessing. If you already switched, open Klox on this PC after install, or on a phone that still has the app, and remove the leftover row. Change the password if you are not sure who held the old Linux login. Password reset is not this article's novel. It is the obvious next move when a machine sat unlocked with two accounts.

Family math lives in the five-device article. I will not rebuild the household spreadsheet. PC you still own plus phone is the common kit for this URL. After a clean remove, you are back to the ones that are actually tunneled. Ghost sessions are how people think a Linux user switch uses extra licenses. There are no extra licenses. There are leftover peers. Five means five connected at once. You can install in more places.

Yearly from $2.83 a month does not buy a sixth seat while a second Linux login retries a name the server still holds. Seven-day first purchase if you only bought to try a tunnel and you are inside the clock. Refunds: /refund. A user switch is not a refund reason by itself. A user switch is not a first-purchase coupon. If you already had a year, a new local account does not restart that clock.

Sleep is not disconnect. A lid that still held a peer under the old user still counted until the handshake died. After the switch the corpse can sit. Look. Do not buy a second year because a farm said new user needs a new license. It does not.

Two Linux accounts are not two Klox seats by themselves

A seat is a live handshake on this PC. OS profiles do not mint extra slots. If Connect is up, you spent one. If it dropped, Connect again under the account you use.

A leftover row from the old login is a corpse, not a second laptop

Old name plus new handshake is one radio wearing two labels until you remove the old one. Then this PC is one seat. Count the phone separately if it is tunneled.

PolicyKit and the tun interface may already exist; Allow is still this user's job

The installer adds a tun or WireGuard interface. A reinstall of Linux deletes it. A user switch often does not. The interface can still sit from the old install. First Connect under the new profile may still ask. PolicyKit will ask this session. Allow it. Deny is how people decide a new GNOME user hated VPNs. The product did not hate them. They denied the interface.

I will not invent a tun versus wg picker as a consumer protocol. Protocols remain WireGuard, OpenVPN, OpenConnect, and Shadowsocks. WireGuard first. OpenVPN when UDP is rude. Do not add a VPN in GNOME Settings and pick a random IKEv2 row you typed by hand. That built-in row is not Klox. Two tunnels is how you get none. The KloxVPN on a Linux Desktop: Packages, NetworkManager, CLI article owns package versus NetworkManager versus CLI once the binary actually runs under this user. This page exists so you remember the leftover is the profile, not the disk.

Another VPN leftover can own the route if you installed a trial from a banner during first-run of the new account. Remove that. Then ours. Two privileged interfaces fighting is a support ticket that starts with I switched user and nothing works. Split the jobs. Linux user is the distro. Binary is /download under this login if it is missing. Interface is Allow. Protocol is WireGuard unless the cafe is rude.

ufw or firewalld stays on if you already run it. I will not paste a ruleset that opens the world. Turning the shield off to make VPN work is how a new profile becomes a hobbyist lab. You wanted a hop. You did not want an open inbound day. If you did not add those rules, do not start now as a personality. If you did, allow the VPN interface. The Windows firewall article is not this OS.

If Connect works on the old Linux user and fails on the new one, the usual miss is the PolicyKit prompt this session has not seen, or the launcher this profile does not have, or sudo this uid does not have. Run the package again if the desktop never asked. Then Connect. Approve the sheet. First handshake on a network you already trust. Do not debug both logins at once in a cafe.

Wayland versus X11 does not change WireGuard. It changes whether a tray icon appears. Same sentence as the reinstall essay, on purpose, because people still blame the compositor. If the tray is missing after a fresh user, the tunnel can still be up. Look at the app window.

Deny on PolicyKit is how Connect fails on the new profile

No permission for this session, no tunnel. Run the package again if the desktop never asked. Then Connect. Approve the sheet. First handshake on a network you already trust.

A GNOME VPN row you typed is not a Klox protocol

Klox ships WireGuard, OpenVPN, OpenConnect, and Shadowsocks. A handmade IKEv2 row is a different product. Do not stack it under our tray icon and then ask why both look disconnected.

Live USB, ARM, and a wipe you did not run are forks

A live session is RAM. Persistence is a disk you meant. If you booted try-without-installing and never wrote the internal drive, the VPN on a Linux Live USB: Ephemeral Session, Persistence, Matching Arch article owns that chair. Reboot throws the client away unless you built persistence. This page assumes an installed root you kept, plus a second login on that root. I will point at the stick. I will not reprint Ventoy, casper-rw, or prefer-the-phone-on-someone-else's-PC so two URLs compete. If the machine under the stick is not yours, that essay already said stop.

Architecture still matters after you create a local user. Snapdragon Linux, a Pi you use as a desktop, an ARM laptop: still ARM packages. Intel and AMD still want amd64. A new GNOME user does not pick your CPU. People who just escaped a user wizard grab the first Linux button they see and then decide VPNs are broken. They grabbed amd64 on ARM, or the reverse. The VPN on Linux ARM: Pick the ARM .deb or .rpm, Not AMD64 article owns that picker. I will point. I will not reprint the uname screenshot so three URLs compete.

The Chrome extension is on Download as browser-only traffic. After a new Linux user you may only have Firefox or a fresh Chromium. The extension is not a NIC. Slack and the mail app stay in the clear. If you truly only needed that browser, install the extension and be honest about the leftover. For a system tunnel on this PC, you still need the package, PolicyKit, interface. Do not treat the extension as a user-switch recovery SKU.

A wipe you ran is the reinstall article. If you erased the disk and then created a second user on the fresh install, you have two articles. Read both. Do not paste one checklist into both days. Empty root first. Then this leftover if you immediately made another login and the first home still held a tray you never launched here.

Windows ARM packages are a different OS. If this laptop dual-boots after you created a Linux user, that is two articles. Do not grab the Windows ARM .exe because you just read ARM in a forum. You are on Linux until you are not. Mac is a different family. Universal .dmg. Not this page. A Steam Deck is typically AMD64 and a different chair. I will not turn this user-switch page into a Deck guide.

Arch, Gentoo, Nix: we still do not ship a fourth package. If you created a second user on Arch, configs exist. The desktop article already said that. I will not invent an AUR name. If a neighbor packaged it, that is the neighbor, not Klox QA. Ticket the tunnel, not the missing pacman name.

Do not switch a Linux user you do not own. Work laptop. School image. A friend's PC you are fixing without asking. A machine you found. Stop. I will not coach a new local admin on a disk that is not yours. I will not coach bypassing LUKS. I will not coach skipping a work or school account. I will not coach a VPN as a cloak for that. If it is employer property, IT owns the accounts. If it is a school device, the AUP still exists. If it is not yours, it is not yours.

A live stick is RAM unless you meant persistence

Installed root plus a second login: this page. Try-without-installing: live USB article. Do not paste this checklist onto a session that dies when you pull the stick. Persistence is their plot, not ours.

Do not switch a Linux user you do not own

Work: IT. School: AUP. Borrowed: ask, uninstall when you leave. Do not install Klox as a workaround. Do not mint a local admin because a blog ranked privacy.

First Connect on a network you already trust, then the desktop habit

First handshake should happen on home Wi-Fi or Ethernet in the kitchen. Confirm WireGuard comes up. Open a boring site. Then pack. A hotel splash plus a first-ever PolicyKit prompt on a new Linux user is how people decide the login hated VPNs. The product did not hate them. The garden raced the tunnel.

Once the package actually runs under this account, the order is the KloxVPN on a Linux Desktop: Packages, NetworkManager, CLI habit: official file, one owner, WireGuard first, OpenVPN if the network is rude, this PC is one of five. I will not reprint that list so two URLs compete. This page exists so you remember why you are doing the list again: the profile forgot the binary, or never had it. Config export still exists for NetworkManager and wg-quick. The /linux-vpn landing is the config-shaped cousin. If you hopped onto a distro we did not package, import a config. Do not run the GUI and NetworkManager at the same time and then ask why the default route looks haunted. That sentence is louder after a user switch, because the old uid may still own a system connection.

Autostart, if the app shows the row, means connect on untrusted Wi-Fi. A cafe SSID is untrusted. A house SSID you run can be marked however the app lets you. I will not invent a toggle named On Demand. If the row is missing, you have a Connect button. Use the button after the splash, same as any other day. A new Linux user does not mint a special auto-connect.

Do not skip because the app felt slow once. Switch protocol. WireGuard first. OpenVPN when UDP is rude. If both fail on a network you trust, wait. A cafe is not the spare tire for a rude first handshake. A rude first handshake is a reason to stay in the kitchen until a boring site loads through the hop. Cookies on klox.app remain at /cookie. A Linux user switch is not a cookie. A leftover seat is not a cookie. Do not file a cookie ticket because a new profile still showed a peer. That peer is this article. Proton's Linux download ranking is not your leftover. Download the matching package under the account you live in. Count the seats. Leave Linux users you do not own alone.

The old Linux user can stay on the disk. That is allowed. Uninstall Klox there only if it was a per-user copy you will not launch again, so the tray does not surprise the next person who still uses that login. If the package is system-wide in /usr, uninstalling from the old user uninstalls it for this one too. Look before you feel brave. If nobody uses that login, the distro's user list is their product. I will not write a userdel novel. I will tell you not to delete a home that still holds files you need. Look at Documents on that user before you type -r.

DNS through the tunnel is a client claim on the app. A raw config you imported after copying the old home might still point at last year's resolver. If names leak, that is the DNS article and a leak test, not a reason to recreate the user twice. Check the connection. Do not type a public resolver as a hobby. We are not selling a custom-DNS picker in this post.

Seven days is not a user-switch coupon. First purchase, seven days, /refund. If you already had a year, a new local account does not restart that clock. Same email. Same five seats. Yearly from $2.83 a month on the seats that remain. No city count. No portal URL. Cookie policy at /cookie.

Kitchen first, cafe second

Confirm a boring site through the hop at home under this Linux user. Then travel. A splash plus a fresh PolicyKit prompt is a bad first rehearsal. The desktop article owns the portal pause.

Seven days is not a user-switch coupon

First purchase, seven days, /refund. Not a Linux-user gift. If you already had a year, a new login does not restart that clock. Same email. Same five seats.

Key Takeaways

A Linux user switch on a PC you still own is the matching .deb or .rpm from /download under that user if the client is per-user, package manager, PolicyKit Allow, then the live app for any leftover slot. Prefer disconnect before a login change you plan. The distro owns the accounts. Klox does not. amd64 versus ARM still matters after you create a local user. The desktop article owns the taps once the binary runs here.

This is not a Linux reinstall, not a live USB, not a Windows .exe leftover, not a Mac listing leftover. A second Linux user is not a reinstall. Do not switch a Linux user you do not own. Do not treat a GNOME logout as a Klox logout. Laptop you kept plus phone is still the household math. Five means five.

Yearly from $2.83 a month on the seats that remain. Seven-day first purchase if you are inside the clock. No city count. No portal URL. Cookie policy at /cookie. If you wanted an empty disk, that article is next door. If you wanted a live stick, Windows user switch, or macOS user switch, those pickers are next door too. If you wanted a hop on the Linux login you now live in, download the matching installer under that user, approve the interface, and remove the corpse if it still sits.

Install Klox under the Linux user you now live in

KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. After you switched Linux user on a PC you still own, get amd64 or ARM .deb/.rpm from /download under that user. Remove leftover slots in the live app.

Download KloxVPN

Frequently Asked Questions

If this account cannot see the client, yes. Open /download, pick amd64 or ARM, .deb or .rpm, install with the package manager under that user, sign into the same Klox account, allow PolicyKit. If the menu already launches Klox here, skip the second copy. The old slot may still sit until you remove it in the live app.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.