Split tunneling lets selected applications or destinations bypass the VPN while other traffic remains protected. It can solve compatibility problems, preserve access to local devices and reduce unnecessary routing, but it also creates two network paths with different privacy properties. A safe configuration begins by deciding exactly what may leave outside the encrypted tunnel.
Full tunnel versus split tunnel
With full tunneling, supported internet traffic travels through the VPN connection. With split tunneling, chosen apps, ports, subnets or websites use the regular connection instead. The precise controls differ by NordVPN app and operating system, so instructions for Windows may not match Android or Linux.
Traffic excluded from the VPN exposes the normal public IP and is visible to the local network and internet provider according to the underlying protocol. Split tunneling is therefore a routing choice, not a way to give every app simultaneous VPN protection and direct-network compatibility.
When split tunneling can help
- Accessing a printer, NAS or smart device on a trusted local network.
- Keeping a latency-sensitive game outside the VPN while protecting a browser.
- Using a work application that rejects VPN addresses.
- Routing only a sensitive application through the VPN.
- Avoiding unnecessary bandwidth use for a trusted local service.
How to plan the configuration
- List the applications that genuinely require bypass access.
- Choose the narrowest available exclusion rather than excluding a broad browser.
- Enable split tunneling in the current NordVPN app for the platform.
- Add one app or rule and test its public IP and connectivity.
- Confirm protected apps still show the VPN IP.
- Recheck the rules after app or operating-system updates.
A browser contains email, cloud storage, payments and extensions, so excluding the entire browser can expose far more than the one website causing trouble. A dedicated secondary browser profile or specific application may offer a cleaner separation.
Security and privacy risks
Excluded traffic is not protected by the VPN tunnel. On public Wi-Fi, that creates a meaningful exposure and may undermine the reason for using a VPN. Malware entering through an excluded app can still affect the device and data shared with protected applications.
DNS behavior can also cause confusion. An excluded application may use the normal IP while DNS requests follow different settings, producing location mismatches or service failures. Test with reputable IP and DNS leak tools, but remember that test pages only describe the browser opening them.
Split tunneling and Kill Switch
Do not assume the Kill Switch blocks deliberately excluded traffic. Split-tunnel rules are intended to permit some traffic outside the VPN, while Kill Switch behavior varies by platform and mode. Test an intentional VPN disconnect with a non-sensitive connection to understand the actual result.
Common mistakes
- Excluding a whole browser for one incompatible site.
- Using split tunneling on an untrusted hotspot without reviewing exposure.
- Forgetting background services associated with an excluded application.
- Assuming mobile and desktop apps provide identical controls.
- Ignoring DNS or local-network leaks after a change.
When full tunneling is better
Use full tunneling when privacy is more important than a small performance benefit, when using unfamiliar networks or when you cannot clearly identify which traffic is excluded. Simplicity is a security advantage: fewer routes mean fewer assumptions to test.
NordVPN split tunneling is most effective as a precise exception to a full-tunnel default. Keep the exception list short, document why each rule exists and remove it when the compatibility need ends.
Official topic reference: NordVPN Blog — VPN split tunneling.