☁️ Cloud XpertSystemsSecure Communication & Networking Products
VPN concepts

What Is Split Tunneling?

Last reviewed: September 1, 2026

Split tunneling lets some traffic use the VPN while other traffic uses the normal network path. That flexibility can be useful, but it also means not every application or destination receives the same VPN protection.

Full tunnel and split tunnel in one example

In a full-tunnel design, traffic covered by the VPN profile is routed through the VPN. In a split-tunnel design, rules decide which applications, networks or destinations use the VPN and which continue directly through the local internet connection.

Why people use split tunneling

The privacy tradeoff

Traffic excluded from the VPN is not protected by the VPN tunnel. It may use the normal public IP and the local network path. That is not necessarily a leak if it is an intentional rule, but users should know which traffic is intentionally outside the tunnel.

Split tunneling can complicate troubleshooting

If one application works and another does not, or two applications appear to use different public IP addresses, split-routing rules may be involved. Before changing DNS or reinstalling the client, confirm whether traffic is intentionally divided.

Split tunneling and kill switches are different

A split-tunnel rule says where traffic should go. A kill switch says what should happen when a protected VPN path is unavailable. The two features can interact, but they solve different problems.

Common ways split-tunnel rules are expressed

Split tunneling can be based on applications, destination networks, IP ranges, local networks, or routing tables. A work VPN may send only corporate subnets through the tunnel, while a consumer client may let the user select applications to include or exclude. These designs produce similar user-visible results but are implemented differently.

How to verify a split-tunnel configuration

Test the public IP from an application that should use the VPN and from one that should not. If local-network access is intentionally preserved, confirm that printers or other local services remain reachable. Document the intended behavior before troubleshooting so an intentional direct route is not mistaken for a leak.

Frequently Asked Questions

Does split tunneling mean the VPN is leaking?

Not necessarily. Traffic outside the tunnel can be intentional. A leak is unintended exposure contrary to the expected configuration.

Can I use local devices while connected to a VPN?

That depends on the client and routing policy. Some configurations intentionally preserve access to local networks.

Is full tunnel always better?

It is simpler from a privacy perspective because more traffic follows one protected route, but split tunneling can be useful when compatibility or local access matters.

Related reading

What Is a VPN Kill Switch?

A plain-English explanation of VPN kill switches, what they do when a tunnel drops, what they do not protect, and why behavior differs by device and VPN client.

Readers who want to test these concepts with a VPN client can use the ZBEVPN Download page. For connection-specific problems, start with the Guides & Knowledge Center.