What Split Tunnelling Is and When to Use It
Short answer
Split tunnelling sends only selected apps or destinations through the VPN and leaves everything else on your normal connection. It keeps local devices working and avoids the speed cost on traffic that gains nothing from the tunnel. The risk is forgetting what is excluded, which is how people end up assuming they are protected when they are not.
On this page
By default a VPN client takes everything. Every application, every connection, including the ones that gain nothing from being routed through a server in another city and lose measurable speed by going there.
Split tunnelling is the setting that stops that. You nominate what goes through the tunnel and what does not, and the operating system routes accordingly.
It is genuinely useful and it introduces exactly one risk, which is that your understanding of what is protected drifts out of alignment with what the configuration actually does.
How the split is decided
Two ways, and most clients offer only one.
By application. You name which apps go through the tunnel, or which bypass it. Android has first-class support for this at the system level, and Windows and macOS clients commonly implement it. It is the more intuitive model and the one most people want.
By destination. You specify IP addresses, address ranges or domains that bypass the tunnel. More precise, considerably more fiddly, and the only option available at router level.
Both come in two polarities:
- Exclude mode — everything goes through the tunnel except the things you list. Safer default, since forgetting an app leaves it protected.
- Include mode, sometimes called inverse split tunnelling — nothing goes through except what you list. Right when the tunnel is for one specific job.
Choose exclude mode if the VPN is your general privacy arrangement. Choose include mode if it exists to reach one work system.
What is worth excluding
| Traffic type | Exclude? | Why |
|---|---|---|
| Local network devices | Yes | Printers and NAS boxes are not reachable through a tunnel |
| Video calls | Usually | Latency-sensitive, already encrypted |
| Online games | Yes | Latency is the whole experience |
| Banking apps | Often | Some flag VPN connections as suspicious |
| Streaming | Depends | Excluding fixes blocks, and removes the protection |
| Software updates | Reasonable | Large, slow through a tunnel, signed anyway |
| Browsing | No | This is the traffic the VPN exists for |
The local network row is the one that solves a real complaint. A full tunnel sends traffic destined for your own printer out to a VPN server, which has no idea what to do with it. Most clients have an allow local network access option that handles this without configuring anything else; use that before building a split tunnel rule for it.
The banking row is worth a note. Some banks treat a connection from a datacentre address as a risk signal and respond with extra verification or an outright block. That is their fraud system doing its job, and excluding the app is the practical answer.
Setting it up
- Android (system level): Settings → Network & internet → VPN → the gear next to your VPN. Per-app controls appear here on many devices, and some VPN apps offer their own list that is easier to manage.
- Windows and macOS clients: usually Settings → Split Tunnelling, with a choice of mode and a list you add applications to. Add the executable, not a shortcut.
- iOS: generally unavailable in consumer apps. iOS does not expose the routing control required, and anything claiming otherwise is usually doing something narrower.
- Routers: the equivalent is policy-based routing, where you assign devices or destination ranges to the tunnel or around it. Firmware support varies and stock firmware often lacks it entirely. Setting up a router VPN covers what to check.
After any change, verify by opening an IP-checking site in each application that matters. A browser you excluded will show your real address; one you did not will show the server’s. Checking in one browser tells you nothing about the other.
The failure mode
Here is how it goes wrong, and it is always the same story.
Someone excludes their browser to fix a streaming block or a slow page load. Three months later they use that browser for something they assumed was protected. The configuration is doing exactly what it was told; the person’s mental model is from before they changed it.
Two habits prevent it:
- Exclude applications with a single obvious purpose. A game, a video-call app, a printer utility. Not a browser, which you will use for everything.
- Write down what you excluded. A note in the VPN client’s own settings screen counts, since that is where you will look.
If you find yourself tempted to exclude a browser, consider installing a second browser for the excluded traffic instead. The separation then becomes visible rather than invisible.
How corporate VPNs use it
Worth understanding separately, because the reasoning is almost the opposite of a home user’s.
Organisations historically forced a full tunnel so that every packet from a company laptop passed through corporate filtering and logging. When most staff worked in an office, the handful of remote connections cost nothing.
Remote working broke that arithmetic. Routing an entire workforce’s video calls through a single appliance and a single office internet line is exactly the capacity problem that makes corporate VPNs crawl at nine in the morning. What a concentrator is covers why the bottleneck sits where it does.
The common response is a carefully limited split: conferencing services and a few large cloud applications are excluded, everything else stays inside. It is a deliberate trade of visibility for capacity, decided centrally, and it is not something you can change from your laptop. If your work VPN excludes video calls and you were wondering why, that is why.
When it diagnoses a problem for you
Split tunnelling is also a useful troubleshooting tool. If a site is failing and you cannot tell whether the VPN is responsible, temporarily excluding that one application answers the question in seconds without disconnecting the tunnel and disrupting everything else.
Where the symptom is a site refusing to load while the VPN reports connected, the connected-but-blocked triage works through the possibilities in order.
Realistic expectations
A sensible split tunnel on a laptop excludes two or three things: local network access, a video-call application, and perhaps a game. That removes most of the friction people experience with a full tunnel while leaving browsing protected.
The honest limit is that split tunnelling makes a VPN harder to reason about, and the whole value of a privacy tool depends on reasoning about it correctly. If you cannot say from memory what is excluded, you have configured too much and should go back to a full tunnel with local network access permitted.