How split tunneling works
By default, a VPN app sends everything from your device through its tunnel. This is called a full tunnel. With split tunneling, the app gives the operating system a set of rules, and each connection is sorted as it starts: into the tunnel, or straight out through your regular network.1
| Type | How it sorts traffic | Example |
|---|---|---|
| By app, exclude | Everything uses the VPN except the apps you pick | A banking app that refuses VPN connections goes direct |
| By app, include | Only the apps you pick use the VPN | Just your browser is tunneled |
| By address | Traffic to certain IP ranges goes one way, the rest goes the other | Your home network stays local so you can reach a printer |
The building blocks come from the operating system and the VPN protocol. Android lets a VPN app name the apps that are allowed into the tunnel or kept out of it, and apps kept out use the network as if the VPN weren’t running.2 In WireGuard, each connection has a list of allowed IP ranges that decides which traffic enters the tunnel.3
Why people use split tunneling
- Local devices. Printers, smart speakers and casting to a TV often need a direct connection on your home network.
- Apps that block VPNs. Some banking and streaming apps refuse to work through one.
- Speed where privacy isn’t the point. A large game download can go direct while your browsing stays in the tunnel.
What to watch for
Anything you exclude behaves as if you had no VPN. The sites and services those apps reach see your real IP address, and your network and internet provider see where that traffic goes. A kill switch protects the tunnel, not the apps you chose to leave outside it. A good rule is to exclude as little as possible, and to exclude specific apps instead of including only a few.
Where you’ll see it
In consumer VPN apps, split tunneling is a setting where you tick the apps to exclude or include. In workplaces, it usually means the opposite arrangement: only traffic for the company network goes through the company VPN, and everything else goes directly to the internet.1
Split tunneling in Secria VPN
Secria VPN has split tunneling: you choose what goes through the VPN and what uses your normal connection. It comes with VPN Plus and Secria Pro. Everything inside the tunnel is protected with WireGuard plus ML-KEM-1024.
Related terms
Sources
- NIST Computer Security Resource Center, Glossary: split tunneling.
- Android Developers, VpnService.Builder (addAllowedApplication and addDisallowedApplication).
- WireGuard, Conceptual overview: cryptokey routing.
Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.
Questions about split tunneling
Is split tunneling safe?
It is as safe as your choices. Traffic inside the tunnel is protected as usual. Traffic you exclude is exposed to your network and shows your real IP address, so only exclude apps where that doesn’t matter.
Should I turn on split tunneling?
Only if something needs it, such as a printer on your home network or an app that won’t work through a VPN. If everything works with the full tunnel, leaving split tunneling off protects the most.
What is the difference between split tunneling and a full tunnel?
A full tunnel sends all of your device’s traffic through the VPN. Split tunneling sends some through the VPN and lets the rest use your normal connection.
Does split tunneling make a VPN faster?
It can for the traffic you exclude, because that traffic skips the VPN server. Traffic inside the tunnel runs at the same speed as before.