Skip to main content

Control how your traffic is routed with VPN split tunneling for business

Choose which destinations use the VPN tunnel and which bypass it to balance security, performance, and network efficiency.

14-day money-back guarantee

NordLayer gateway page showing teams, servers and split tunneling settings excluding Google Meet and Microsoft Teams

OFFICIALLY ENDORSED

Chosen by industry experts and thought leaders 

Join 15,000+ business teams worldwide who trust NordLayer for fast, reliable network protection, with split tunneling VPN built into every plan.

G2 and Geekflare Summer 2026 awards for fastest implementation, best support, user recommendation, and value

OVERVIEW

What is VPN split tunneling?

VPN split tunneling gives you control over how your network traffic is routed by allowing you to choose which traffic goes through an encrypted VPN tunnel and which connects directly to the internet. Instead of sending all traffic through the VPN, split tunneling lets organizations define which destinations require VPN protection and which can benefit from a direct connection.

Smiling professional at laptop with Smart Routing and Encrypted Protection features highlighted

FUNCTIONALITY

How does VPN split tunneling work?

Split tunneling applies routing rules that decide which traffic uses the VPN tunnel and which traffic bypasses it, and NordLayer gives you 3 ways to set those rules.

VPN tunnel diagram showing encrypted traffic flow from user device to cloud services and P2P networks

Include mode

Route selected IP addresses and subnets through the VPN tunnel, while all other traffic connects directly to the internet, so access to private resources stays protected without pulling everyday browsing through your gateway.

Exclude mode

Route everything through the VPN tunnel by default, and name the exceptions, so protection stays broad while services like video conferencing platforms or VPN-restricted sites connect directly for better performance.

URL-based split tunneling

Set domain-level exceptions through the NordLayer browser extension for Chrome, Firefox, Brave, and Edge, so a named site bypasses the tunnel while the rest of your browsing stays protected, with no client reconfiguration needed.

benefits

Why use split tunneling?

Full tunneling sends every packet through your gateway, costing you speed, bandwidth, and infrastructure headroom. Split tunneling lets you decide where protection is worth the overhead and where a direct connection would be a better fit.

Improve your network performance

Route latency-sensitive traffic like video calls straight to the internet, so your team stops blaming the VPN for a frozen meeting.

Maintain security where it matters

Critical traffic stays inside the encrypted tunnel under admin-defined policy, so nothing bypasses the VPN unless you decide it should.

Reduce infrastructure load and cost

Take unnecessary traffic off your gateways and corporate network, freeing bandwidth and delaying the next capacity upgrade.

Set the rules once, apply them everywhere

Define the routing policy per team from the Control Panel and roll it out across every device without touching a single endpoint.

COMPARISON

Split tunneling vs. full tunneling: which routing model fits your network?

Full tunnel VPN

A full tunnel VPN routes everything through your gateway by default, which gives you complete visibility over every session at the cost of speed and capacity.

Every connection leaves the device through the encrypted tunnel, regardless of destination.

Latency-sensitive traffic like video calls competes with everything else for gateway capacity. 

Gateway capacity has to scale with total traffic, including traffic that gains nothing from encryption.

One unified routing policy covers everyone, with little flexibility to tune it per user or team.

Environments where every session has to be inspected or logged centrally.

Split tunneling

Split tunneling lets you decide which destinations need the tunnel, so protection stays on your private resources while everything else takes the direct route.

You define which destinations use the tunnel and which connect directly.

Traffic that does not require inspection takes the fastest route available. 

Only the traffic you nominate reaches the gateway, so capacity goes further.

Include, exclude, and URL-based rules are set per team from the Control Panel.

Teams balancing protection with day-to-day performance across mixed workloads.

Start split tunneling your traffic from just $11 per user/month

NordLayer pricing comparison showing Core and Premium split tunneling features from eleven dollars per user

Split tunneling is available on the NordLayer Core plan from just $11 per user/month. Upgrade to NordLayer Premium from just $14 per user/month to add URL-based split tunneling. Both plans require a 5 user minimum and offer a 14-day money-back guarantee. 

USE CASES

3 big problems split tunneling helps solve

Improve video conferencing performance

Allow collaboration platforms to bypass the VPN tunnel while keeping other traffic protected.

Access VPN-restricted services

Create exceptions for websites or services that do not work properly through VPN connections.

Optimize remote work connectivity

Balance secure access to company resources with fast access to public internet services.

GETTING STARTED

How to set up VPN split tunneling

Follow these 3 simple steps to enable NordLayer VPN split tunneling across your network.

  1. 1

    Sign up for NordLayer

    Choose our Core or Premium subscription plan and download the NordLayer app.

  2. 2

    Enable split tunneling

    Pick include, exclude, or URL-based mode and define which destinations will use the tunnel.

  3. 3

    Roll it out to your teams

    Apply the policy in the Control Panel and your team gets faster connections without losing protection.

NordLayer + CrowdStrike: secure your network and endpoints all at once

With threats coming from all sides, your business can’t afford to leave anything unprotected. NordLayer and CrowdStrike secure both your company network and employee devices, so your teams stay safe and productive.

  • Monitor and control who can access your company network.

  • Stop threats like malware and phishing with AI-powered protection.

  • Keep your business compliant with the latest data security standards.

Get a real-time look at how NordLayer protects businesses

Explore features like Custom DNS, a dedicated IP, VPN Split Tunneling, and more, all in real-time with our interactive Control Panel demo.

NordLayer usage dashboard showing active VPN sessions over time with line graph

MORE INFORMATION

Frequently asked questions

There are 3 common types. Application-based split tunneling routes traffic based on which app is making the request. IP or subnet-based split tunneling routes traffic based on the destination address, which is what NordLayer’s include and exclude modes use. URL- or domain-based split tunneling applies rules to specific websites, which NordLayer supports through the browser extension.

Yes, NordLayer allows you to control which traffic goes through the VPN tunnel and which traffic bypasses it. With split tunneling, you can use include mode to route selected IP addresses or subnets through the VPN tunnel while other traffic connects directly to the internet. Alternatively, you can use exclude mode to allow specific IP addresses, subnets, or domains to bypass the tunnel. The browser extension also supports URL-based split tunneling for managing domain-based exceptions.

Split tunneling and full tunneling differ in how traffic is routed. Full tunneling sends all network traffic through the VPN tunnel, providing centralized security and control. Split tunneling allows organizations to choose which traffic uses the VPN tunnel and which traffic bypasses it, helping balance security, performance, and access requirements. NordLayer supports flexible split tunneling options with include, exclude, and URL-based modes to adapt routing based on organizational needs.

The risk with split tunneling is that traffic leaving the tunnel is no longer inspected or encrypted by the VPN, so a poorly scoped rule can send sensitive traffic over an untrusted network. NordLayer removes most of that exposure by keeping the decision with the administrator rather than the end user. Exclude mode protects everything by default and only releases the destinations you name, so the safe path is the one you get unless you actively change it. Every rule is set and audited from the Control Panel.

Split tunneling is as safe as the policy behind it. Traffic that bypasses the tunnel takes the same path as any ordinary internet connection, so if a device is working from a compromised network, that traffic is exposed in the same way normal browsing would be. What keeps that from reaching the rest of your network is scoping the exceptions tightly, keeping private resources inside the tunnel, and applying the rules centrally instead of letting users configure their own. With NordLayer, administrators define every exception from the Control Panel and can pair split tunneling with a Kill Switch, so protected traffic never falls back to an unsecured connection.

To disable split tunneling, administrators can turn off the feature in the relevant gateway or browser extension settings. After disabling split tunneling, traffic will no longer follow custom routing rules and will instead use the default VPN routing behavior.

No, not all VPNs offer split tunneling. Split tunneling requires advanced traffic routing capabilities that allow users or administrators to define which traffic goes through the VPN tunnel and which traffic bypasses it. NordLayer provides flexible split tunneling options with include and exclude modes, helping organizations balance security, performance, and network efficiency.

No, split tunneling and a VPN kill switch are different NordLayer security features. Split tunneling gives administrators control over traffic routing by defining which destinations use the VPN tunnel and which bypass it. A VPN Kill Switch prevents data exposure by blocking internet access if the VPN connection is interrupted. Together, these features help organizations balance security, reliability, and performance.