What Is Split Tunneling, and When Should You Use It?
By default, a VPN routes every app and process on your device through its encrypted tunnel. Split tunneling lets you choose specific apps -- or specific traffic -- to bypass the tunnel and go directly to the internet instead.
Why you'd want to exclude an app from the VPN
Some banking apps and services actively reject connections from VPN IP ranges. Some local network devices (a printer, a smart TV, a NAS) only work correctly when your device is on the same local network segment as them, which a full-tunnel VPN can interfere with. And some traffic -- like a large local backup -- has no reason to add VPN overhead at all.
The trade-off
Anything excluded from the tunnel loses the VPN's protection and shows your real IP address to that destination. Split tunneling is a deliberate trade: you're choosing convenience or compatibility for specific apps in exchange for giving up the VPN's coverage for exactly those apps.
Typical ways to configure it
- App-based: pick specific apps to include or exclude from the tunnel.
- Destination-based: exclude specific domains or IP ranges (useful for local network devices).
- Inverse split tunneling: route everything through the VPN except the apps you explicitly exclude, which is the safer default for most people.
Should most people use it?
If you've never hit a specific compatibility problem, there's no need to turn it on. It's a targeted fix for a targeted problem -- a banking app that blocks VPNs, a smart-home device that needs local discovery -- not a setting to enable by default.