Split tunneling is a feature that lets you choose which apps or IP addresses use the VPN and which connect directly to the internet.
This is useful when you want some traffic protected by the VPN while allowing other apps to use your regular internet connection. For example, you might route your web browser through the VPN while allowing a local printer, streaming app, or online game to connect directly.
This guide explains how Private Internet Access (PIA)’s Split Tunnel works and how to configure it on Windows, macOS, and Linux.
Jump To…
What You Can Do with PIA’s Split Tunnel
Configure the All Other Apps Rule
What You Can Do with PIA’s Split Tunnel
Split Tunnel gives you control over which traffic uses the VPN. You can:
-
Bypass the VPN for specific apps: Selected apps use your regular internet connection, while all other apps use the VPN.
- Example: Let your banking app use your regular connection while your web browser stays protected.
-
Restrict specific apps to the VPN only: Selected apps always use the VPN, while all other apps use your regular internet connection.
- Example: Route your web browser through the VPN while games or video conferencing apps connect directly to the internet.
-
Bypass the VPN for specific IP addresses: Exclude individual IPv4/IPv6 addresses or entire subnets from the VPN, while all other traffic continues to use the VPN.
- Example: Access a local server directly without disconnecting the VPN.
- Control DNS behavior (Windows and Linux): Choose whether DNS requests follow your Split Tunnel rules or always use the DNS server configured in the PIA app.
Enable Split Tunnel
- Open the PIA app, select the three-dot menu, and choose Settings.
- Open the Split Tunnel tab and turn on the feature.
|
Note: Enabling Split Tunnel may require additional permissions, depending on your operating system:
|
Add an Application
- Select Add Application.
- Choose an application from your desktop device. Then, select one of the following options:
- Bypass VPN: The app connects directly to the internet without using the VPN.
- Only VPN: The app can access the internet only while the VPN is connected.
Add an IP Address or Subnet
Unlike application rules, IP address rules can only be used to bypass the VPN. Traffic sent to the specified IP address or subnet will use your regular internet connection, while all other traffic continues to follow your Split Tunnel rules.
- Select Add IP Address.
- Enter the IPv4 or IPv6 address (or subnet) and click OK.
Set DNS Behavior
On Windows and Linux, Split Tunnel also controls how DNS requests are handled.
- Follow App Rules: DNS requests follow the same Split Tunnel rules as the application. Apps that use the VPN also use the DNS server configured in the PIA app, while apps that bypass the VPN use your system's default DNS settings.
- VPN DNS Only: All DNS requests use the DNS server configured in the PIA app, regardless of whether an application uses or bypasses the VPN. This helps ensure your DNS queries are always resolved through the VPN's configured DNS provider.
Configure the All Other Apps Rule
The All Other Apps option in the Split Tunnel tab determines how applications without a Split Tunnel rule are handled.
- Use VPN: All apps use the VPN by default. Only apps you set to Bypass VPN connect directly to the internet.
- Bypass VPN: All apps bypass the VPN by default. Only apps you set to Only VPN use the VPN connection.
This setting lets you decide whether the VPN protects all applications by default or only the ones you explicitly choose.