Flex-VPN

Flex-VPN Journal

VPN Split Tunneling: How It Routes Traffic

Split tunneling sends selected traffic through the VPN while keeping the rest on the regular connection. It can preserve fast local access and reduce unnecessary load on the protected route.

This material explains lawful network security and configuration scenarios. Follow the rules that apply in your location.

Two routes instead of one

A full tunnel sends all device internet traffic to the VPN server. Split tunneling applies rules so selected apps, domains or networks use the tunnel while the rest goes directly through the provider.

Rules may include selected traffic or exclude selected traffic. In include mode only listed items use the VPN; in exclude mode everything except the list uses it.

When it helps

A direct route can be convenient for local network devices, a printer, banking app or regional service that expects the usual IP. The VPN route can remain for work systems, public Wi-Fi and apps where traffic protection matters.

Splitting also reduces data sent through the VPN server and may lower latency for nearby services.

App and domain rules

App rules are easier to reason about because all traffic from one program follows a route. Domain rules are flexible, but a service may use many support domains, CDNs and addresses. An incomplete list creates mixed behavior.

Start with a small rule set and expand after testing. Broad wildcards may unexpectedly change unrelated destinations.

DNS and route consistency

DNS resolution and the resulting connection should follow compatible rules. Otherwise a name may resolve through one channel and connect through another, causing delays or errors. Follow the guidance for the specific client.

After every change, check the public IP in an app or browser meant to use the VPN and separately in an excluded app.

A safe setup order

Make the full tunnel stable first. Then enable split tunneling, add one rule and test on both Wi-Fi and mobile data. Keep the original profile so you can return to a known working configuration.

Split routing improves convenience, but direct traffic does not receive VPN tunnel protection, so every exception should be intentional.

Frequently asked questions

Does split tunneling reduce security?

Only for traffic intentionally left on the direct route. That traffic is outside the VPN tunnel, so rules should be selected carefully.

Can traffic be split by app?

Yes, when the client supports it. App-level rules are often easier to maintain than domain lists.

Why does a website rule work only partly?

The site may load resources from other domains and CDNs. Add related destinations or use an app-level rule.

Flex-VPN

Ready to set up a connection?

Choose a plan for three devices and receive the connection profiles in Telegram.

Open bot