Split Tunneling Guide: Selective VPN Routing
Split tunneling allows you to choose which traffic goes through your VPN and which accesses the internet directly. This comprehensive guide covers everything you need to know about selective routing with FreeGuard VPN.

Split Tunneling Guide: Selective VPN Routing

Split tunneling allows you to choose which traffic goes through your VPN and which accesses the internet directly. This comprehensive guide covers everything you need to know about selective routing with FreeGuard VPN.

TL;DR (Quick Summary)

  • Split tunneling routes some traffic through VPN, some directly
  • Benefits: Better speeds for local services, maintain VPN for privacy
  • FreeGuard’s approach: GeoIP-based routing (by destination region)
  • Use cases: Local banking, regional streaming, work applications
  • Setup: Settings → GeoIP Region → Select region

What Is Split Tunneling?

Split tunneling divides your internet traffic into two paths:

Your Device
    │
    ├── Protected Traffic → VPN Tunnel → Secure Access
    │
    └── Direct Traffic → Normal Internet → Local Services

Types of Split Tunneling

Type Routes Based On FreeGuard Support
GeoIP-based Destination country ✅ Built-in
App-based Which application 🔜 Coming soon
Domain-based Website address Manual (advanced)
Port-based Network port Manual (advanced)

FreeGuard currently implements GeoIP-based split tunneling, which routes traffic based on where it’s going geographically.

Why Use Split Tunneling?

Benefits

Benefit Explanation
Faster local services No VPN overhead for regional traffic
Better compatibility Local services that block VPNs work normally
Reduced VPN load Lower bandwidth through VPN servers
Maintained privacy International/sensitive traffic still protected

When Split Tunneling Helps

Problem 1: Bank blocking VPN

Without split tunneling:
Bank → Sees VPN IP → "Suspicious login attempt" → Blocked

With split tunneling (bank's region enabled):
Bank → Sees your real IP → "Normal login" → Allowed

Problem 2: Local streaming service

Without split tunneling:
Local service → Detects foreign VPN IP → "Not available in your region"

With split tunneling:
Local service → Sees your real regional IP → Content plays normally

Problem 3: Work requires local IP

Without split tunneling:
Work system → VPN IP doesn't match policy → Access denied

With split tunneling:
Work system → Your real local IP → Access granted

How FreeGuard’s GeoIP Routing Works

The Process

  1. You select a region (e.g., US, CN, JP)
  2. FreeGuard loads IP database for that region
  3. Traffic is analyzed: Where is it going?
  4. Routing decision:
    • Destination in selected region → DIRECT
    • Everything else → VPN TUNNEL

Example: GeoIP CN Enabled

Traffic to Alipay (China IP) → DIRECT → Works normally
Traffic to WeChat (China IP) → DIRECT → Works normally
Traffic to Google (US IP) → VPN → Protected access
Traffic to Netflix (US IP) → VPN → Protected access
Traffic to Unknown site → VPN → Protected by default

Setting Up Split Tunneling

Basic Setup (GeoIP)

  1. Open FreeGuard on your PC
  2. Go to Settings
  3. Find GeoIP Region
  4. Select your region (CN/US/JP/KR/RU/IR/ID/AE)
  5. Save and Reconnect

Choosing the Right Region

If you need… Select…
Chinese local services CN
US banking/services US
Japanese content JP
Korean apps KR
Russian services RU
Iranian local access IR
Indonesian services ID
UAE local services AE

Disabling Split Tunneling

  1. Go to Settings
  2. Set GeoIP Region to Off
  3. Save and Reconnect
  4. All traffic now goes through VPN

Advanced Split Tunneling Scenarios

Scenario 1: Expat Banking Access

Situation: American living in Germany, needs Chase Bank access

The problem: Chase flags logins from German VPN servers

Solution:

  1. Connect to FreeGuard (server doesn’t matter)
  2. Enable GeoIP: US
  3. Chase traffic goes direct (your German IP)
  4. Other US sites work through VPN

Wait, why does this work?

Chase just wants consistent login patterns. Your German IP is fine as long as it’s consistent. The VPN IP changing each time was the trigger.

Scenario 2: Gaming with Regional Content

Situation: Playing game with Japan-only events while abroad

The problem: Game detects VPN, locks regional content

Solution:

  1. Enable GeoIP: JP
  2. Game server traffic goes direct
  3. General browsing protected
  4. Regional content accessible

Scenario 3: Work + Personal Separation

Situation: Remote worker needs work VPN and personal privacy

Challenge: Work requires specific regional IP

Solution:

  1. Enable GeoIP for work region
  2. Work applications see direct IP
  3. Personal browsing through FreeGuard
  4. Maintain separation

Scenario 4: China Travel

Situation: Visiting China, need both local and international access

Challenge: VPN for international; direct for Chinese services

Solution:

  1. Use Trojan protocol (best for China)
  2. Enable GeoIP: CN
  3. WeChat, Alipay work (direct)
  4. Google, social media work (VPN)

Split Tunneling Security Considerations

What’s Protected vs Exposed

Traffic Path Security
Matching GeoIP region Direct ISP can see
International VPN Encrypted
DNS (default) VPN Protected

Security Best Practices

Do:

  • Only enable GeoIP for trusted local services
  • Keep sensitive browsing on VPN
  • Disable GeoIP on untrusted networks

Don’t:

  • Enable GeoIP just for speed gains
  • Use split tunneling on public Wi-Fi
  • Route sensitive personal data directly

When to Avoid Split Tunneling

  • High-security browsing: Journalism, activism, sensitive research
  • Public networks: Airports, cafes, hotels
  • Unknown networks: Friends’ Wi-Fi, conference networks
  • Maximum anonymity: When you need complete privacy

Troubleshooting Split Tunneling

Issue: Local Service Still Blocked

Symptoms: GeoIP enabled but service doesn’t work

Causes:

  1. Service uses CDN in different country
  2. Service performs additional checks
  3. IP database doesn’t include all IPs

Solutions:

  1. Clear cookies and cache
  2. Try different browser
  3. Some services may have additional blocks

Issue: VPN Traffic Slower Than Expected

Symptoms: With GeoIP enabled, VPN traffic seems slower

Cause: Normal variation, or comparing to direct traffic

Reality check: Direct traffic (GeoIP) is always faster than VPN traffic. This is expected.

Issue: Not Sure If Working

Test method:

  1. Enable GeoIP for a region
  2. Visit a service in that region → Should work
  3. Visit ipinfo.io → Should show VPN IP
  4. If both work correctly → Split tunneling working

Issue: Some Sites Within Region Go Through VPN

Cause: IP database gaps for some services

Explanation: Not every IP in a country is in the database. Some may be:

  • Recently allocated
  • Third-party CDN
  • Miscategorized

This is normal and doesn’t indicate a problem.

Comparing Split Tunneling Approaches

GeoIP vs App-Based

Feature GeoIP (FreeGuard) App-Based
Ease of setup ★★★★★ ★★★
Granularity Country-level Per-app
Maintenance Automatic Manual
Flexibility Limited High
Use case Regional services Specific apps

GeoIP vs Domain-Based

Feature GeoIP (FreeGuard) Domain-Based
Setup One dropdown List domains
Coverage All regional IPs Specified only
Updates Automatic Manual
For Regional bypass Specific sites

Performance Impact of Split Tunneling

Speed Benefits

Trafiktype Uden Split Tunneling Med Split Tunneling
Lokale tjenester VPN-overhead Direkte (hurtigere)
Internationalt VPN-hastighed VPN-hastighed (samme)
Samlet Konsekvent Varierer efter destination

Fordele ved båndbredde

Split tunneling reducerer belastningen på VPN-serveren:

  • Lokal videostreaming: Direkte (sparer VPN-båndbredde)
  • Lokale downloads: Direkte (sparer VPN-båndbredde)
  • International browsing: VPN (beskyttet)

Ofte stillede spørgsmål

Kan jeg route specifikke apps, ikke kun regioner?

I øjeblikket understøtter FreeGuard GeoIP-baseret routing. App-baseret routing er planlagt til fremtidige opdateringer.

Fungerer split tunneling på mobil?

GeoIP-routing i FreeGuard er i øjeblikket tilgængelig på PC. Understøttelse af mobil varierer efter platform.

Vil split tunneling ødelægge noget?

Sjældent. De fleste problemer er:

  • Tjenester, der specifikt kræver VPN (bruger allerede VPN-bypass)
  • Tjenester med flere regionskontroller

Er split tunneling mindre sikkert?

For direkte trafik, ja - den er ikke krypteret. Det er afvejningen for kompatibilitet. Lad følsom trafik forblive på VPN.

Kan min ISP se min split-tunnelerede trafik?

Ja. Direkte trafik går normalt gennem din ISP. De kan se, at du tilgår disse tjenester (men ikke indholdet, hvis HTTPS).

Bruger split tunneling mere batteri?

Lidt. Processen med at træffe routingbeslutninger tilføjer minimal overhead. Den samlede effekt er ubetydelig.

Næste skridt


Sidst opdateret: January 2026