Skip to main content
LiMP VPN
All posts

How to Set Up VPN Split Tunneling by App in 2026

How to Set Up VPN Split Tunneling by App in 2026

In short: Split tunneling is a VPN feature that sends only selected apps through the encrypted tunnel while the rest of your traffic goes directly. That keeps your browser and messengers protected while banking and government apps, local devices (printer, smart home) and heavy traffic run as usual. Setup is most flexible on Android, where the VPN can be turned on per specific app. On iPhone, system-level per-app VPN is mostly available through corporate profiles, so traffic is usually split a different way. Below is how it works, which apps to route around the VPN and which through it, and how to set it all up.

What is split tunneling in simple terms

Split tunneling is a mode in which the VPN protects only part of your device's traffic rather than all of it. One data stream goes through the encrypted VPN tunnel, and another goes directly through your ISP with your normal IP address. You decide which apps or sites enter the tunnel and which stay outside it.

The name captures the idea exactly: a single traffic stream is «split» in two. An ordinary VPN wraps everything into the tunnel, while split tunneling lets you draw a line — keeping private services protected without getting in the way of apps that a VPN only hinders. To understand what actually happens to data inside the tunnel, it helps to first learn how a VPN works.

This split resolves a common conflict: you don't always need a VPN for everything. A banking app may refuse to work from an unfamiliar IP, a local printer becomes unreachable, and a video call loses speed because of the extra hop. Split tunneling fixes this without forcing you to turn protection off entirely each time.

How split tunneling works: two modes

Split tunneling rests on two opposite modes, and it's important not to confuse them during setup. The mode decides what is protected by default and what stays outside.

ModeHow it worksWhen it fits
Inclusive: only selected apps through the VPNAll traffic goes directly, and only the marked apps go through the tunnelYou need the VPN only for a couple of private apps; everything else as usual
Exclusive: everything through the VPN except selected appsAll traffic is protected, and the marked apps are routed directlyYou want the VPN almost everywhere, but banking or government apps must go direct

The exclusive mode suits most people: protection is on by default, and only a few apps that the VPN interferes with are pulled out of the tunnel. The inclusive mode is chosen when the VPN is needed only occasionally. The rule is simple: the more privacy matters, the wiser it is to keep protection on by default and route only exceptions outside.

Pros and cons of split tunneling

Split tunneling is a trade-off between convenience and full protection, and it has both sides. The upsides make everyday VPN use more comfortable; the downsides come from part of your traffic staying outside the tunnel.

ProsCons
Banking and government apps work smoothly from your home IPTraffic outside the tunnel is unencrypted and visible to your ISP
Access to local devices — printer, NAS, smart homeIt's easy to accidentally leave something important outside
Less load on the connection: heavy traffic goes directHarder to keep track of what is protected right now
Battery savings on mobile — not everything is encryptedNot available on every platform or in every VPN app

The main risk is obvious: whatever is routed out of the tunnel loses VPN protection — your ISP sees those connections again, and on public Wi-Fi such traffic is more exposed. So route outside only what genuinely needs a direct connection, and keep everything private inside the tunnel.

Which apps to route through the VPN and which directly

A universal rule: keep everything tied to privacy and data transfer under VPN protection, and route directly only what conflicts with the VPN. Here is the typical split that fits most people.

Through the VPN (in the tunnel)Directly (around the tunnel)
Browser and search appsBanking apps and online banking
Messengers and emailGovernment apps and region-checking apps
Work services with sensitive dataLocal devices: printer, NAS, smart home
Anything used on public networksServices tied to your home IP

The logic is simple. Banking and government apps often block sign-in from an unfamiliar IP or region, so they're easier to leave direct. Local devices on your home network simply aren't visible through the tunnel. Everything touching privacy and use on other people's networks, by contrast, should stay under VPN protection. When in doubt, keep the app in the tunnel: extra protection is safer than an accidental leak.

Types of split tunneling: by app, by IP and by site address

Split tunneling varies by how exactly you draw the boundary, and that determines how finely you can tune the split.

  • By app. You mark specific apps — for example, route a banking app directly and keep a messenger in the tunnel. The most intuitive method; best supported on Android.
  • By IP address. The rule is set for a range of addresses rather than an app. This is how splitting works on iPhone, Mac and many routers, where selecting by app isn't available.
  • By site address (URL). Some services and browser extensions let you route specific domains out of the tunnel — handy when only one particular site is a problem.

The platform usually dictates the method more than your preference: on Android it's easier to split by app, on iOS and routers by IP address. The feature also depends on the VPN app itself — not every service offers split tunneling, and where it exists the set of modes differs.

How to set up a VPN for individual apps on Android

On Android, split tunneling by app is best supported: the system can enable the VPN selectively, and most VPN apps give this feature a convenient interface. Exact menu names differ from service to service, but the logic is the same.

  1. Open your VPN app's settings. Find a section named something like «Split tunneling» or «App management».
  2. Choose the mode. Specify what the list does: route selected apps through the VPN, or route them directly instead.
  3. Mark the apps. From the list of installed apps, pick those the rule applies to (for example, banking — direct).
  4. Save and reconnect. Apply the settings and turn the VPN back on so the rules take effect.
  5. Check the result. Make sure a protected app shows the VPN server's IP and a directly routed one shows your normal IP.

If there's no split tunneling option in the app, update it to the latest version or check the system settings: many Android versions have their own app-exclusion list for the VPN. The basic VPN install on a phone is covered in our guide on setting up a VPN on Android.

How to set up split tunneling on iPhone and Mac

On iPhone and Mac, system-level splitting by app in the usual sense isn't available: iOS doesn't let an ordinary VPN app enable the tunnel for individual programs. So per-app VPN here appears mainly in corporate environments — through management profiles (MDM) configured by a company's IT department.

For personal use, splitting on Apple devices is usually done by IP addresses or domains, if the VPN app offers such a setting. Another working path is to move the split to the router level: then the rule for which devices and addresses go through the tunnel is set once for the whole network. How to install a VPN on iPhone in the normal mode is described in our guide on setting up a VPN on iPhone. If split tunneling is essential for you, choose Android or a service that supports splitting by IP on iOS.

Split tunneling on Windows and routers

On Windows, split tunneling is most often available in the VPN app itself and is set up much like on Android — a list of programs or addresses that go around the tunnel. Usually the service settings have a section like «Split tunneling» or «Exclusions» where you add the apps or sites you need.

On a router, splitting works by devices and IP addresses: you set which network devices go out through the VPN and which go directly. This is handy when, say, a work laptop should go through the tunnel while a TV with a local service goes direct. This approach is often called policy-based routing; more on network-level VPN is in our guide on how to protect your home network with a VPN.

Security: what to keep in mind with split tunneling

The main security rule with split tunneling: anything routed out of the tunnel loses VPN protection completely. That's not a bug but the essence of the mode — yet it's exactly where people slip up, accidentally leaving important traffic outside.

  • Verify the right things are in the tunnel. After setup, confirm that private apps show the VPN server's IP, not your real one. How to check protection works is covered in how to test that your VPN is working.
  • Watch for DNS leaks. Even tunneled traffic can send DNS queries directly and reveal the sites you visit.
  • Remember the kill switch. An internet kill switch works only with traffic going through the VPN; it doesn't cover the apps you routed out.
  • Don't route private traffic out «for speed». Saving a couple of percent of speed isn't worth exposed traffic on a public network.

The sensible approach is to enable split tunneling deliberately and narrowly: route out specific banking or local apps and keep everything else protected. If you're not sure you need this mode, it's safer to keep all traffic in the tunnel.

LiMP VPN and split tunneling

LiMP VPN is a privacy service for iOS and Android billed by a Russian legal entity (LLC LiMP): it encrypts traffic and keeps no connection logs. On Android it's most flexible to manage which apps go through the tunnel and which go directly; on iPhone the split depends on the platform's capabilities. The service runs on the WireGuard protocol, so even a full tunnel has little effect on speed and battery. See what it can do on the features page, and terms and plans on the LiMP VPN pricing page.

Conclusion

Split tunneling turns a VPN into a flexible tool: everything private stays protected while apps the tunnel hinders run directly. It resolves everyday conflicts — banking doesn't block sign-in, the local printer stays reachable, video calls keep their speed. Remember the price of convenience: traffic routed out of the tunnel has no protection, so route outside only what truly needs it. Splitting is most flexible on Android by app; on iPhone and routers, by IP address. Start with the exclusive mode, keep protection on by default, and route out only a handful of apps.

Frequently asked questions

What is VPN split tunneling?

Split tunneling is a VPN mode in which only part of your traffic goes through the encrypted tunnel while the rest connects to the internet directly with your normal IP. You choose which apps or addresses are protected by the VPN and which stay outside — a banking app is convenient to route directly, while a browser stays protected.

How do I set up a VPN for individual apps only?

It's easiest on Android: in your VPN app's settings open the split tunneling section, choose the mode (selected apps through the VPN, or directly instead) and mark the apps you need. After saving, reconnect the VPN and check the IP. On iPhone, splitting by app for personal use is usually unavailable — there traffic is split by IP address or at the router level.

Which apps are best routed out of the VPN tunnel?

Directly, around the tunnel, it's convenient to route banking and government apps (they often block an unfamiliar IP) and services for reaching local devices — printer, NAS, smart home — that aren't visible through the VPN. Everything tied to privacy and use on public networks — browser, messengers, email — is better kept under VPN protection.

Is split tunneling safe?

The mode itself is safe but needs attention: traffic routed out of the tunnel fully loses VPN protection — it isn't encrypted and is visible to your ISP, and on a public network it's more exposed. So route outside only what genuinely needs a direct connection, and keep everything private inside the tunnel. When in doubt, it's safer to keep all traffic protected.

Does split tunneling work on iPhone?

Splitting by specific apps on iPhone for personal use is usually unavailable: iOS doesn't let an ordinary VPN app enable the tunnel selectively per program. Per-app VPN on iOS appears mainly in corporate management profiles (MDM). For personal tasks on iPhone, traffic is split by IP address if the service supports it, or the split is moved to the router.

How to Set Up VPN Split Tunneling by App in 2026 | LiMP VPN