It links docker's network through a linux/windows pipe to a process on your windows/mac host. So containers network packets don't get out from a virtual network adapter (that can be filtered out) but from a vpnkit.exe process on windows.
Using this, you are more compliant with strict corporate security rules and are less likely to be blocked by your VPN client, proxy firewall etc...