VPN Split Tunneling: What It Is and How to Use It | NetGuardVPN
GuideNetGuardVPN8 min read

VPN split tunneling: choose which apps use the VPN

Learn how split tunneling routes selected apps through a VPN, what to consider before excluding traffic, and how to test a rule and undo it safely.

Updated:

What is VPN split tunneling?

Split tunneling lets you route some traffic through a VPN while other traffic uses your regular Wi‑Fi or mobile connection. Depending on the device and VPN client, you might choose apps, network destinations, or routes. For example, you could send a work app through the VPN while letting an app that needs to reach a local printer connect directly.

This is a routing choice, not a separate kind of encryption or an automatic speed boost. It determines which network path a connection takes. Windows VPN routing can use routes to send selected destinations through the VPN while other traffic uses the physical network interface. Android VPN apps can use an allowed-app list or a disallowed-app list. Apple documents per-app VPN as a managed-device capability, where a VPN configuration is associated with managed apps. The options you see therefore depend on your operating system, VPN app, and, in some cases, an organization’s device-management setup. (learn.microsoft.com)

Common approaches include:

  • Route everything through the VPN: Apps use the VPN route while it is connected.
  • Send selected apps through the VPN: Chosen apps use the tunnel; other apps connect directly.
  • Exclude selected apps: Most traffic uses the VPN, except for the apps you exclude.
  • Route by destination: The route depends on the network address being contacted, rather than only on the app.

VPN clients use different labels, such as “split tunneling,” “app exclusions,” “bypass VPN,” or “VPN for selected apps.” Read the explanation next to the setting. A list may identify apps that use the VPN or apps that bypass it—the opposite of what you may assume.

When might split tunneling help?

Different network paths can be useful when an app needs to reach something on your local network, such as a printer or smart-home device. You might also need to separate work and personal traffic if your organization permits it, or choose a VPN route for only the apps that need it.

Some apps or services may not behave as expected over a particular VPN route. An app might depend on access to a local device or on a route chosen by an administrator. Excluding it could help, but it is not a guaranteed fix: DNS settings, the app itself, the network, or the service may be responsible for the issue.

Don’t enable split tunneling just because it sounds faster. Excluded traffic uses a different route and network exit from traffic inside the VPN. If you use a VPN because you want traffic from a particular app to leave through the VPN connection, excluding that app works against that goal.

What happens to traffic outside the VPN?

An app excluded from the VPN uses the device’s regular network route. Websites and services may see the public address provided by your internet or mobile provider rather than the VPN’s exit address. That does not, by itself, identify you, but it does mean the VPN is not handling that app’s traffic in the way it handles traffic inside the tunnel.

DNS routing, access to local devices, and organization-managed network rules may also differ. The details depend on your device and VPN client. Don’t assume an excluded app uses the same DNS path or network restrictions as an app that stays in the tunnel. Check the client’s documentation if those details matter to you.

An app-level rule may not map neatly to every part of an app’s activity. An app can open a link in a separate browser, hand work to a system service, or use built-in components. Platforms and VPN clients may handle these connections differently. Test the specific action you care about, not just whether the app opens.

Allowed-app lists versus exclusions

An allowed-app list usually means that only the apps you select use the VPN. Apps not on the list connect outside it. This can be straightforward when only a few apps need the VPN, but it’s easy to forget to add an app that should use it.

With an exclusion list, most apps use the VPN and the apps you select bypass it. This may suit a setup with just a few exceptions, but it is easy to forget which apps were left outside the tunnel.

Check what the list means in your VPN client before saving it. Android’s VPN APIs let a VPN app specify apps allowed to access the VPN or apps denied access to it; the corresponding API methods cannot be combined in the same builder configuration. Apps excluded this way use the network as if the VPN were not running. This explains the platform’s underlying options, but it does not mean every Android VPN app offers the same controls or labels. (developer.android.com)

Decide what should use the VPN

Start with your goal, not a list of apps. Write down what should use the VPN and why. For example: “The work portal should use the VPN; the local printer should connect directly.” A clear goal makes it less tempting to add exceptions without a reason.

For each app or destination, ask:

  1. Does it need to use the VPN’s network exit? If so, don’t exclude it unless you have confirmed that the rule still routes it through the tunnel.
  2. Does it need local-network access? Some tasks may require direct access to a local device, but test this on your actual network and device.
  3. Does it handle work or managed data? Don’t change settings supplied by your employer or administrator without permission.
  4. Does it rely on another app or service? Check the browser, external link, or system component involved in the action you care about.
  5. Do you understand the effect of bypassing the VPN? If not, keep the default behavior and check your VPN client’s documentation.

For sensitive or unfamiliar apps, avoid adding an exception until you know what it does. Take particular care with email, banking apps, work tools, cloud storage, and password managers. That does not mean a VPN guarantees their safety; it means the network route you choose may be an important part of how you expect them to connect.

A practical setup process

Menu names vary, so use this as a decision process rather than a universal button-by-button guide:

  1. Check your current setup. Confirm that the VPN is connected and the apps you need are working. If useful, note your current VPN mode and server before making a change.
  2. Open the VPN client’s settings. Look for app routing, split tunneling, or exclusions. If the option is missing, the feature may not be supported in that app version or on that platform.
  3. Read the setting’s description. Confirm whether the list contains apps that use the VPN or apps that bypass it.
  4. Add one app or destination. Avoid changing several rules at once; testing will be easier to interpret.
  5. Save and reconnect if the client asks you to. Some changes apply immediately; others require a new VPN connection.
  6. Test the action that motivated the change. If you excluded an app to reach a printer, test printing—not just whether the app launches.
  7. Check an app that should remain on the VPN. Make sure the rule did not affect traffic you meant to keep inside the tunnel.

On Android, an app may offer its own per-app settings; Android’s documentation also describes app-level VPN controls. Apple’s managed per-app VPN associates a VPN configuration with managed apps, so it should not be treated as a universal personal-iPhone toggle. On Windows, split tunneling can use routes that send selected destinations through the VPN and other traffic over the physical interface. The available method depends on the VPN connection type and software. (developer.android.com)

If the setting is controlled by a work profile or device administrator, ask your administrator before changing it. Altering managed routing can affect access to internal resources or conflict with workplace requirements.

How to check that the rule works

Test one rule at a time and focus on the specific app or task. For an app that should use the VPN, check its behavior after applying the rule. If the visible public address matters, use a reputable IP-checking service in the app or browser that actually follows the route you want to test. A result from one browser does not prove that every app on the device uses the same route.

For an excluded app, expect a direct route, subject to the device, network, and VPN client. For an app meant to use the VPN, confirm that the rule is set up accordingly. An IP address shown by a website is only one clue; it does not verify every detail of DNS handling, routing, or system-service behavior.

Test separately on Wi‑Fi and mobile data if you use both. Repeat the check after updating your VPN app or changing the list, since settings or permissions can change. Don’t rely only on the VPN icon in the status bar: it usually indicates connection status, not the route taken by each app.

For a more detailed check of IP, DNS, IPv6, and routing, see our VPN connection testing guide. For help choosing a client for different devices, read our guide to Xray clients.

If an app stops working

First, remove the last rule you added or restore your previous configuration. If the connection recovers, make changes gradually. Then check whether Android is set to block connections outside the VPN. When that blocking option is enabled, apps that do not use the allowed VPN route may lose network access. Google documents this as a way to block traffic that does not use the VPN. Don’t switch it off without understanding why it was enabled. (developer.android.com)

Next, look for overlapping rules in the VPN client, operating system, or work-managed profile. Rules that do not match can produce behavior that is hard to explain from a single toggle. If the issue affects a work resource or internal site, contact your administrator before changing managed settings.

Change only one thing at a time: one app, one routing rule, or one network connection. Note what you changed and what happened. Avoid installing unknown “route repair” tools or copying commands from a guide if you don’t understand their effects. When testing is over, remove exceptions you no longer need.

Common mistakes and a final checklist

Confusing selected apps with excluded apps. Before saving, confirm which apps will go through the VPN.

Assuming a browser represents the whole device. Other apps may use different routes or system components.

Keeping exceptions without a reason. Each exception chooses the device’s regular network route for that traffic instead of the VPN route.

Changing several rules at once. That makes it harder to identify which change caused a problem.

Before you finish, check that:

  • I know whether the list means “use the VPN” or “bypass the VPN.”
  • I have a specific reason for each exception.
  • I have not excluded work or sensitive apps by mistake.
  • I tested the action that motivated the change.
  • I know how to restore the previous setting.
  • If the device is managed by an organization, I have approval to change the rule.

Split tunneling can be useful when different apps or destinations genuinely need different network paths. It is not a universal performance setting or a guarantee of privacy. Start with one clear rule, test it, and keep only the exceptions you still need.

Sources