
Split tunnel is an exception list. Some apps, or some addresses, leave the device without entering the VPN. Everything else still does, if that is the mode you actually have. People hear 'split' and picture two VPNs, or a smarter tunnel that protects the important bits automatically. It is dumber than that. You named a bypass. The bypass is visible to the cafe, the ISP, and whoever else already sat on that path. That is the product. Marketing will dress it as flexibility. Flexibility is a scheduled leak.
This is not VPN Split Tunneling: When to Use It. That piece is when to use it, how people configure it, full tunnel versus split as a checklist. I will not rewrite the steps. This is not White-Label VPN and Split Tunnel Copy. That one is strings on a branded Settings screen: bypass versus exclude. You are a consumer staring at Klox. Confirm the row. Do not invent inverse modes because a competitor screenshot had three radio buttons. This is not When Not to Use a VPN: Skips You Choose on Purpose. That list is skips: portal, printer, bank, LAN game. Printers show up here as the exception physics, not as a skip calendar. This is not the VPN for Home Office: Secure Your Home Network seating chart, though work intranet belongs in one section.
A VPN wraps the path you send through it. Traffic you exclude is not on that path. Wikipedia's VPN page is the noun for the tunnel. RFC 8446 is TLS 1.3 on the website. HTTPS can still lock the bank page while that page's hop skips the VPN. Two locks, one of them off-ramp. Cloudflare's explainer will not draw your exception list.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. DNS through the tunnel. IPv6 leak protection and WebRTC leak blocking on the features list. Smart Connect, if the app shows the row, is untrusted Wi-Fi. Split tunnel, if the app shows the row, is the exception list. If the row is missing, you do not have it. Pause the whole tunnel for the printer. I will not invent a per-app picker so this article matches ExpressVPN's help page. Cookies: /cookie. Privacy: /privacy. Apps: /download.
I have a bias. Full tunnel until you can name the leftover. Exceptions leak on purpose. Leave the list empty on cafe Wi-Fi. Confirm the glass before you believe a blog, including this one.
Related reading: Linux quic_connection_id: Not a VPN Setting and Linux fs_protected_regular: Not a VPN Setting. Linux fs_protected_symlinks: Not a VPN Setting and Linux fs_suid_dumpable: Not a VPN Setting. What is a VPN? and VPN kill switch.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
An exception, not a second VPN
Full tunnel: the default route is the VPN. Apps talk to the virtual adapter. The cafe sees a blob to a VPN server. Split tunnel: you punched a hole. That app, or that IP range, uses the physical NIC like the VPN was never there. You still have one tunnel. You also have a side door. The side door is not encrypted by us. HTTPS may still encrypt the site. RFC 8446 still applies to that site. The hop is local again. Destination IPs, often SNI, DNS for that app if names follow the app, are back on the LAN.
A second VPN would be a second handshake, a second peer, a second seat. Split tunnel is not that. Work VPN plus Klox is two products fighting or cooperating. Exception list is one product with a hole. Mixing those sentences is how people say 'I split so I could run both VPNs' and then neither path is what they thought. Two VPNs is a different headache. This page is the hole.
Open the app. Look for split tunnel, apps excluded, bypass VPN, allow LAN, or a cousin of those words. That is the row. If you see it, exceptions leak on purpose. If you do not see it, this article is vocabulary plus a reason to pause instead of hunt for a hidden lab mode. I will not write click-here steps that assume Windows radio buttons we did not confirm in your build.
Kill switch, if you have that row too, can fight the hole. Fail-closed means nothing leaves without a tunnel. An excluded app wants to leave without a tunnel. One of those wins. If split 'does nothing' and the app still has no internet, the switch may be the parent. Pause the switch to test. I will not claim they always compose. Confirm on a network you control.
- 1Skim the seating / order diagram.
- 2Do the numbered steps once on your real network.
- 3Use the FAQ if a sentence was too long.
- 4Follow one related article — not ten tabs.
How to read this page
| What you wanted | What split actually is | What leaked | If the row is missing |
|---|---|---|---|
| Talk to the printer | LAN IPs or the print app outside the tunnel | That LAN traffic in the clear on your LAN | Pause VPN, print, restore |
| Work intranet | Those hosts or that app outside Klox | Your ISP and LAN see that hop | Use the work VPN, or pause Klox |
| Bank that blocked the VPN IP | Bank app or site outside the tunnel | Cafe or ISP sees the bank hop | Pause, log in on a network you trust, restore |
| A second VPN | Not this. Two clients, two peers | Confusion, often a dead handshake | Do not mash. One tunnel at a time unless IT said otherwise |
| Inverse: only these apps use VPN | Only if the glass has that mode | Everything not listed is a leak | Do not invent it from a competitor screenshot |
| Row missing | You do not have split on this build | N/A | Pause the whole NIC. Download from /download so you have the real client |
An exception is a leak you scheduled. It is not a second tunnel.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
Wikipedia: Virtual private network
ExpressVPN: split tunneling on desktop (competitor specimen)
Confirm the row
Settings, not a blog. If the words are not on the glass, you cannot split. Write support if you expected the row. Do not paste a competitor's three-mode screenshot into a ticket and call it our UI.
The hole is the feature
Success looks like: printer works, and you can say who now sees that traffic. Failure looks like: printer works, and you assume it is still 'on the VPN' because the badge is green. The badge is the other apps.
Printers and NAS
A full tunnel sends 192.168.x.x on a world tour. The packet goes to a VPN node, which has no idea how to reach the USB printer in the hallway, and dies. Or it comes back hairpinned and still dies. That is why people want a hole for local addresses. The hole means those packets stay on the LAN. The LAN can see them. At home, the LAN is you, maybe a guest SSID, maybe an IoT crowd you never patched. At a cafe, 'local' might be other guests. Do not punch a LAN hole on cafe Wi-Fi because you once needed it at home. The exception remembers. You will forget the SSID changed.
NAS, scanners, a desktop you RDP to on the same switch: same physics. Exclude the range or the app if the row exists. Then remember that backups to the NAS are now a clear hop on that LAN. HTTPS does not wrap SMB. The cafe version of this mistake is excluding 'local network' as a lifestyle and then joining airport Wi-Fi with the same profile.
If the row is missing, the honest move is pause Klox, print, restore. Two minutes. The when-not-to-use article already listed that skip. Here the English is: pause is a timed hole for the whole NIC. Split is a standing hole for one path. Standing holes need a reason that is still true. Timed holes expire when you tap Connect again.
Smart home bulbs that need the vendor cloud plus mDNS on the LAN are a mess. Split will not make you a network engineer. If the app is cloudy, it may need the tunnel off to satisfy a vendor that hates VPN IPs, and the LAN on for discovery. That is two leftovers. Name both or leave the lights on a phone that is not tunneled. Five devices means you can leave one phone off Klox as the house remote. That is a seating choice, not a routing thesis.
Home LAN is not cafe LAN
A 192.168 hole at home is a printer. The same hole on a shop AP is other people's laptops. If your client has a per-SSID memory, use it. If it does not, turn split off before you travel. Full tunnel in the shop.
Pause is the row-missing version
Disconnect. Print. Connect. Do not leave disconnected all afternoon because the first page was a shipping label. That conversion from timed hole to forgotten hole is how skip lists get abused.
Work intranet
Intranet hosts often live on private addresses, or on a company VPN that already owns those routes. Adding Klox on top can steal the default route so 10.x.x.x never reaches the office concentrator. Split, if you have it, is how some people keep the browser on Klox and the remote-desktop app on the work path. That is still two leftover maps. The ISP sees the RDP hop if that hop is the exception. The employer sees whatever their agent already saw.
I am not your IT policy. A consumer tunnel on a managed laptop can violate a rule that already has a corporate VPN and an EDR agent. Ask. The home-office guide is the consumer caution. This paragraph is the routing English: intranet traffic that bypasses Klox is not 'still protected by Klox.' It is protected by whatever else is on that path, or by nothing but TLS if the app uses TLS. RFC 8446 does not care which NIC you used. The cafe does.
If work already forced a VPN, you may not need Klox on that machine at all. Two tunnels is how handshakes die. Split will not always compose with Always-on or 'block connections without VPN' on Android. The OS lock wants every packet in a VPN. The exception wants some packets out. The OS usually wins. Then you think split is broken. It is parented.
Do not exclude the whole browser so that one intranet tab works. The rest of the browser's tabs leak too. Exclude the remote-desktop binary if the row is app-based. If the row is only app-based and intranet is a website, you may have to pause, use a second browser profile without Klox, or use the work client. Ugly. Honest. Inventing a per-hostname mode we did not ship is how tickets rot.
Ask before you punch a hole on a work PC
If the laptop is not yours, split can be a policy problem, not a printer problem. The home-office URL is the wider habit. Here: name the observer on the excepted hop. If you cannot, do not except it.
Do not exclude the whole browser
One tab is not a process. The process is the browser. All tabs share the hole. A dedicated app or a pause is cleaner than teaching Chrome to leak as a lifestyle.
Banks that hate the IP
Shared VPN egress looks like fraud to some banks. Extra captchas. A hard block. An SMS that says a login from another country. The farm fix is 'split the bank app.' The leftover is: that login now uses your real IP on whatever network you are sitting on. At home, maybe you accept that. On cafe Wi-Fi, you just took the app you care about most and handed its hop to the shop. HTTPS still wraps the password in transit to the real bank. RFC 8446. The shop still sees that you talked to a bank. Phishing still works if you typed into a fake host. A hole does not authenticate the site.
I would rather you pause Klox at home, log into the bank, restore, than leave a standing exception that follows you to a hotel. Standing exceptions are how people 'fix' a block once and leak for a year. If the row exists and you still want it, put the bank app on the list, and turn the list off when you travel. If you cannot remember to toggle, do not use the list. Pause per session.
We do not sell a consumer dedicated IP. A dedicated IP is how some people stay tunneled and still look residential. We did not invent that SKU in this sentence. Do not wait for it. The honest tools are pause, split if the row exists, or use the bank on a network the bank already likes.
OpenVPN versus WireGuard will not charm a fraud engine that keyed on the exit address. Switching protocol is for rude APs, not for banks. Switching server might change the reputation of the IP. It might not. Chasing exits to please a bank is a hobby. Budget the pause instead.
Cafe plus bank exception is the wrong stack
The shop is why you wanted the tunnel. The bank is why you punched the hole. Together they cancel the reason you sat down with a VPN. Pause at home. Or use cellular for the bank and Wi-Fi plus tunnel for the rest.
HTTPS still is not a tunnel
The padlock on the bank is the site lock. The exception turned off the hop lock. You still want the real hostname. Autofill on a lookalike is the password-manager article. Split will not save you from a fake domain.
What you just leaked
Say it out loud. Excepted traffic is visible to the local network and to the ISP, the same way it was before you paid $2.83 a month. Contents of HTTPS pages are still wrapped. Names and IPs for that app may not be. DNS is the messy one. Some clients force all DNS through the tunnel even when an app is excluded. Some do not. I will not invent Klox's DNS behavior for excepted apps as a guarantee. If names for the printer still go through us, the printer may even break because the LAN hostname resolved wrong. If names go around us, the ISP gets that name. Test on a network you own. The leak-test article is the procedure for a full tunnel. Split makes that procedure lie if you only test the browser you did not exclude.
WebRTC can still embarrass a page you opened in a tunneled browser. IPv6 can still sneak if v6 is excepted in spirit but not blocked. Features lists those protections for the connected session. An excepted app is not that session. Do not quote the features page as a blanket over the hole.
Kill switch off plus split plus cafe Wi-Fi is three ways to talk in the clear. Pick fewer. My stack on untrusted Wi-Fi is full tunnel, switch on after the splash, split off. Home printer days are split or pause, switch maybe off so the hole can breathe. Two profiles in your head. One green badge cannot remember both.
Five devices do not share an exception list unless the product says they do. The laptop list is not the phone list. You will fix the printer on Windows and then wonder why the Android app still cannot see the NAS. Per device. Per row. Download the real client from /download so you are not configuring a cousin app's UI from memory.
Test the excepted app, not only the browser
IP-check pages in Chrome do not speak for the bank binary you excluded. If you needed proof, check that app's idea of its IP, or accept that you cannot and treat it as clear.
Features-page sentences stop at the hole
Tunnel DNS, IPv6 leak protection, WebRTC blocking: connected path. The exception is another path. Quote them for Connect. Do not quote them for bypass.
Inverse split if the row exists
Some clients offer two directions. Exclude list: these apps skip, the rest use the VPN. Include-only, sometimes called inverse: only these apps use the VPN, everything else skips. Inverse is a huge hole with a small lock. An empty include list can mean nothing is tunneled, or everything is, depending on the vendor. I will not guess which. If Klox's glass does not show an include-only mode, you do not have it. Stop. The ExpressVPN help page I linked as a specimen documents their modes. Their modes are theirs.
If you do see only-these-apps-use-VPN, read it twice. Then list the browser, mail, and anything that talks. Miss the updater and the updater talks in the clear. Miss the store and purchases leak. Inverse is for people who want one app protected on a machine that must otherwise stay local. It is not a default. Default off. Full tunnel is still the default I want.
Do not combine inverse with a kill switch without a test. Fail-closed plus 'most things must skip' is a contradiction some stacks resolve by bricking the skips. Then inverse looks broken. Then you disable the switch forever. Then cafe day leaks on drop. One fight at a time.
I will not draw a matrix of Windows versus Android versus iOS for Klox. Confirm the build. iOS is often the missing row. Missing is allowed. Pause is the fallback. Inventing inverse because a YouTube video used another brand is how you spend an hour in Settings that do not exist.
Empty list is a loaded gun
Exclude empty: usually full tunnel. Include empty: maybe no tunnel. If you cannot tell from the helper text, do not use inverse. Full tunnel. Printer pause. Live.
Their screenshot is not our row
Competitor help pages are specimens. Steal the idea that modes need words. Do not import their radio buttons into a Klox ticket. Open our app. If the mode is absent, it is absent.
When to leave it off
Leave split off on networks you do not run. Cafe, hotel, airport, school guest, the shop with a voucher page. Full tunnel after the splash. The splash itself is a pause, then Connect, then do not reopen the exception list because the printer at home is still on the list. That list traveled in your profile.
Leave it off if you cannot name the leftover in one sentence. 'I might need it' is not a sentence. 'The Brother on 192.168.1.50 must stay local at home' is a sentence. Write the sentence. If it expires, delete the exception.
Leave it off if kill switch and split fight and you need fail-closed more than you need the NAS this week. You can print on Saturday with a pause. You cannot un-leak Tuesday's cafe mail. Yearly from $2.83 a month is cheap enough that the tunnel should win the argument more often than the printer.
Leave it off if the row is missing. Hunting for a hidden split is how people disable random adapters and then file 'VPN broke Windows.' Download a fresh build if you think you are on an old client. Still missing? Pause. The how-to guide will not materialize a picker. Neither will this page.
Travel profile versus home profile
If the client cannot remember per SSID, you are the profile. Home: maybe a LAN hole. Bag: full tunnel. Toggle before you leave the house, not after the airport AP already has your bank exception.
Missing row is not a defect you can will away
Platform binaries differ. White-label copy told brands not to advertise a row they did not ship. Same rule for you as a reader. Absence means pause. Presence means leak on purpose.
How this differs from the how-to
The how-to is a procedure: what split is, when to use it, when to avoid it, how people configure it, routing tables as a sketch. This page is the English you keep after you close the procedure. Exception. Leak. Confirm the row. Printer. Intranet. Bank. Inverse only if the glass has it. Off on cafe Wi-Fi. Pause if there is no row.
The white-label article is for the person who writes 'bypass VPN' on a branded screen. Wrong audience. Wrong chair. If you are a brand, go there. If you are a person with five devices and a Brother printer, stay here, then download the apps and look. Yearly from $2.83 a month. WireGuard first. OpenVPN when the AP is rude. Seven days on first purchase if the client will not do what a farm screenshot promised. /refund. Store purchases follow the store.
I linked a competitor help article so you can see a real exception UI. Use it as a specimen of the idea. Do not treat their invert mode, their website exclusions, or their DNS claims as ours. Their DNS-through-tunnel-even-when-split sentence is theirs to prove. Ours is: DNS through the tunnel on a connected session, and I will not extend that sentence over a hole I have not confirmed on your OS.
If you wanted skips as a calendar, when-not-to-use is next door. If you wanted home office seating, that guide exists. If you wanted steps, the how-to exists. If you wanted a hole you understood, this was the vocabulary. Full tunnel until the leftover has a name. Then a small hole, or a pause. Then restore.
One afternoon of chores
Open Klox. Find split or admit it is missing. Empty the list if you travel. Print with a pause once so you know the move. Connect on the next cafe after the splash. That afternoon beats another feature page.
The default stays full
Exceptions are for leftovers you can say out loud. The badge staying green is not a reason to collect holes. Download the client. Use Connect. Punch a hole only when the printer, the intranet, or the bank has already demonstrated the need.
Key Takeaways
Split tunnel is an exception list, not a second VPN. Traffic on the list skips the hop on purpose. The cafe and the ISP can see that hop again. HTTPS may still lock the page. The map still leaks. Confirm the row in the app. If the row is missing, pause, do the local job, restore. Do not invent inverse modes.
Printers and NAS want a LAN hole at home, not on shop Wi-Fi. Work intranet is a policy plus a route. Banks that hate the IP want a pause more than a standing exception that follows you to a hotel. Inverse, if the glass has it, is a huge hole. Leave split off on networks you do not run.
Klox is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day first-purchase money-back. DNS through the tunnel is the connected path, not a blanket over the hole. Smart Connect, if the row exists, is untrusted Wi-Fi. Read /privacy and /cookie. Download the apps and look at the glass. The how-to is next door if you wanted steps. This page was the English: a hole is a leak you scheduled.
Related Resources
Full tunnel until you can name the leftover
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. Split tunnel only if the app shows the row. Exceptions leak on purpose. Download the client and confirm the glass.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.