Split tunneling creates deliberate exceptions
A full-tunnel configuration sends covered device traffic through the VPN. Split tunneling excludes selected applications or destinations, or includes only selected traffic. That can be useful for local devices, banking apps, streaming services, or work systems that reject VPN addresses.
The privacy trade-off is straightforward
Traffic that bypasses the VPN uses its normal network path. That may expose its destination and source address to the parties that would normally see them. The exception is not necessarily a leak; it may be exactly what the user configured.
Document your exclusions
If you enable split tunneling, keep the list short and intentional. After app updates or device migrations, verify the exclusions again. When troubleshooting a service that shows your normal address, check split-tunnel settings before assuming the VPN failed.
Use full tunnel when simplicity matters
A full tunnel is easier to reason about because fewer routing exceptions exist. Split tunneling is valuable when you have a specific compatibility or performance need. Choose based on the application rather than enabling exceptions by default.
Sources & further reading
This guide is general educational material. Platform behavior, provider policies, and network conditions can change. Check current documentation before relying on a specific configuration.
Report an error or suggest a clarification ↗