Skip to main content
FixMyTech

What Split Tunnelling Is and When to Use It

By

Published

7 min read

Share

Short answer

Split tunnelling sends only selected apps or destinations through the VPN and leaves everything else on your normal connection. It keeps local devices working and avoids the speed cost on traffic that gains nothing from the tunnel. The risk is forgetting what is excluded, which is how people end up assuming they are protected when they are not.

On this page

By default a VPN client takes everything. Every application, every connection, including the ones that gain nothing from being routed through a server in another city and lose measurable speed by going there.

Split tunnelling is the setting that stops that. You nominate what goes through the tunnel and what does not, and the operating system routes accordingly.

It is genuinely useful and it introduces exactly one risk, which is that your understanding of what is protected drifts out of alignment with what the configuration actually does.

How the split is decided

Two ways, and most clients offer only one.

By application. You name which apps go through the tunnel, or which bypass it. Android has first-class support for this at the system level, and Windows and macOS clients commonly implement it. It is the more intuitive model and the one most people want.

By destination. You specify IP addresses, address ranges or domains that bypass the tunnel. More precise, considerably more fiddly, and the only option available at router level.

Both come in two polarities:

  • Exclude mode — everything goes through the tunnel except the things you list. Safer default, since forgetting an app leaves it protected.
  • Include mode, sometimes called inverse split tunnelling — nothing goes through except what you list. Right when the tunnel is for one specific job.

Choose exclude mode if the VPN is your general privacy arrangement. Choose include mode if it exists to reach one work system.

What is worth excluding

Traffic type Exclude? Why
Local network devices Yes Printers and NAS boxes are not reachable through a tunnel
Video calls Usually Latency-sensitive, already encrypted
Online games Yes Latency is the whole experience
Banking apps Often Some flag VPN connections as suspicious
Streaming Depends Excluding fixes blocks, and removes the protection
Software updates Reasonable Large, slow through a tunnel, signed anyway
Browsing No This is the traffic the VPN exists for

The local network row is the one that solves a real complaint. A full tunnel sends traffic destined for your own printer out to a VPN server, which has no idea what to do with it. Most clients have an allow local network access option that handles this without configuring anything else; use that before building a split tunnel rule for it.

The banking row is worth a note. Some banks treat a connection from a datacentre address as a risk signal and respond with extra verification or an outright block. That is their fraud system doing its job, and excluding the app is the practical answer.

Setting it up

  • Android (system level): Settings → Network & internet → VPN → the gear next to your VPN. Per-app controls appear here on many devices, and some VPN apps offer their own list that is easier to manage.
  • Windows and macOS clients: usually Settings → Split Tunnelling, with a choice of mode and a list you add applications to. Add the executable, not a shortcut.
  • iOS: generally unavailable in consumer apps. iOS does not expose the routing control required, and anything claiming otherwise is usually doing something narrower.
  • Routers: the equivalent is policy-based routing, where you assign devices or destination ranges to the tunnel or around it. Firmware support varies and stock firmware often lacks it entirely. Setting up a router VPN covers what to check.

After any change, verify by opening an IP-checking site in each application that matters. A browser you excluded will show your real address; one you did not will show the server’s. Checking in one browser tells you nothing about the other.

The failure mode

Here is how it goes wrong, and it is always the same story.

Someone excludes their browser to fix a streaming block or a slow page load. Three months later they use that browser for something they assumed was protected. The configuration is doing exactly what it was told; the person’s mental model is from before they changed it.

Two habits prevent it:

  • Exclude applications with a single obvious purpose. A game, a video-call app, a printer utility. Not a browser, which you will use for everything.
  • Write down what you excluded. A note in the VPN client’s own settings screen counts, since that is where you will look.

If you find yourself tempted to exclude a browser, consider installing a second browser for the excluded traffic instead. The separation then becomes visible rather than invisible.

How corporate VPNs use it

Worth understanding separately, because the reasoning is almost the opposite of a home user’s.

Organisations historically forced a full tunnel so that every packet from a company laptop passed through corporate filtering and logging. When most staff worked in an office, the handful of remote connections cost nothing.

Remote working broke that arithmetic. Routing an entire workforce’s video calls through a single appliance and a single office internet line is exactly the capacity problem that makes corporate VPNs crawl at nine in the morning. What a concentrator is covers why the bottleneck sits where it does.

The common response is a carefully limited split: conferencing services and a few large cloud applications are excluded, everything else stays inside. It is a deliberate trade of visibility for capacity, decided centrally, and it is not something you can change from your laptop. If your work VPN excludes video calls and you were wondering why, that is why.

When it diagnoses a problem for you

Split tunnelling is also a useful troubleshooting tool. If a site is failing and you cannot tell whether the VPN is responsible, temporarily excluding that one application answers the question in seconds without disconnecting the tunnel and disrupting everything else.

Where the symptom is a site refusing to load while the VPN reports connected, the connected-but-blocked triage works through the possibilities in order.

Realistic expectations

A sensible split tunnel on a laptop excludes two or three things: local network access, a video-call application, and perhaps a game. That removes most of the friction people experience with a full tunnel while leaving browsing protected.

The honest limit is that split tunnelling makes a VPN harder to reason about, and the whole value of a privacy tool depends on reasoning about it correctly. If you cannot say from memory what is excluded, you have configured too much and should go back to a full tunnel with local network access permitted.

Frequently asked questions

Does split tunnelling make a VPN less secure?
It narrows what is protected rather than weakening the protection itself. Traffic inside the tunnel is exactly as encrypted as before; excluded traffic simply travels as it would with no VPN at all. The risk is a mental model that does not match the configuration.
Is split tunnelling available on iPhone?
Generally not in consumer apps, because iOS does not expose the per-app routing control that Android does. Some corporate VPN configurations achieve something similar through managed profiles, but it is not a setting most users can enable.
What is inverse or reverse split tunnelling?
The opposite default, where everything stays on your normal connection and only the apps you name go through the VPN. It suits the case where you need the tunnel for one or two specific things, such as a work application.
Why does my VPN break my printer or network drive?
Because a full tunnel routes everything to the VPN server, including traffic meant for devices on your own network. Enabling the client's local network access option, or adding those addresses to a split tunnel exclusion, restores them.
Can split tunnelling leak my real IP address?
Only for the applications you excluded, which is working as configured rather than a leak. The common mistake is excluding a browser for speed and then using that browser for something you expected the tunnel to cover.

All VPN guides