Split Tunneling
Route some apps or websites through the VPN while others use the direct connection.
How It Works
The VPN client creates a virtual network adapter with a custom routing table. For IP-based split tunneling, routes for specific destinations are added to the main routing table with a lower metric than the VPN's default route, causing those destinations to bypass the tunnel. For application-based split tunneling (available on Windows, Android, and some third-party clients), the client hooks into OS process creation events and applies routing policy per executable using Windows Filtering Platform or Linux cgroups/network namespaces, redirecting only the selected applications' traffic into the VPN interface.
Advantages
- Preserves direct local network access (printers, NAS, Chromecast, smart home devices) while the VPN is active for other traffic
- Reduces VPN bandwidth usage and server load by routing local/regional services through the direct connection
- Allows simultaneous access to region-locked streaming services through the user's local ISP connection and privacy-sensitive traffic through the VPN
- Improves performance for latency-sensitive applications (gaming, VoIP) that may suffer from VPN routing overhead
Disadvantages
- Misconfigured split tunneling can leak the user's real IP address if traffic expected to go through the VPN takes the direct route
- DNS queries for split-tunneled traffic may leak DNS information to the ISP if not carefully routed
- Application-based split tunneling has limited OS support; it works reliably on Windows and Android but is unavailable on iOS and limited on macOS
- Increases configuration complexity; users must understand which applications or destinations should or should not use the VPN
Security Impact
Moderate negative risk; split tunnels create a path where traffic bypasses VPN encryption. If misconfigured, they can expose the user's real IP address and DNS queries. The feature requires careful configuration to maintain the intended security posture.
Performance Impact
Positive for split traffic, which uses the direct connection at full ISP speed. VPN traffic is unaffected and experiences normal VPN overhead. Overall effective throughput improves since only selected traffic is encrypted and routed.
Ideal For
Providers with Split Tunneling(8)
CyberGhost
Romania-based VPN with 11,690+ servers in 100 countries, dedicated streaming profiles, and strong privacy protections outside 14 Eyes.
ExpressVPN
Premium VPN with TrustedServer RAM-only infrastructure, custom Lightway protocol built in Rust, and 105 country locations.
Mullvad
Privacy-first VPN with RAM-only servers, anonymous signup, post-quantum encryption by default, and WireGuard-only infrastructure.
NordVPN
9,400+ servers in 224 locations worldwide. NordLynx protocol, post-quantum encryption, and independently verified no-logs policy.
Private Internet Access
Proven no-logs VPN with unlimited simultaneous connections, port forwarding, MACE ad-blocker, and a massive 10 Gbps server network.
Proton VPN
Swiss-based VPN with a generous free tier, Secure Core architecture, open-source apps, and independently audited no-logs policy.
Surfshark
Feature-packed VPN with unlimited simultaneous connections, RAM-only servers, CleanWeb ad blocking, and patented Everlink technology.
Windscribe
Generous free tier with 10 GB/month, unlimited simultaneous connections, unique R.O.B.E.R.T. custom DNS blocking, and IPv6 support.