Documentation Index

Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt

Use this file to discover all available pages before exploring further.

How to enable split tunneling via the Control Panel

Prev Next

NordLayer allows you to customize your internet traffic routing with split tunneling. There are two split tunneling modes:

  • Include — only the specified addresses are encrypted and routed through the NordLayer tunnel. All other traffic uses the direct internet route.
  • Exclude — all traffic is encrypted and routed through the NordLayer tunnel except for the specified addresses, which bypass the tunnel and use the direct internet route.
Note

Split tunneling only impacts the flow of IP traffic. DNS requests are still resolved by the gateway and are subject to DNS filtering and Web Protection policies.

Where each mode is available

  • Include mode can be enabled on a Gateway.
  • Exclude mode can be enabled on a Gateway or a Browser Extension.

Each mode supports different address types (up to 100 entries):

  • Gateway — Include supports IP addresses and subnets.
  • Gateway — Exclude supports IP addresses, subnets, and domains/subdomains.
  • Browser Extension — Exclude supports domains/subdomains and wildcards.

How to enable split tunneling on a Gateway

  1. Navigate to Network and select Gateways.
  2. Select the gateway you want to configure and click on it.
  3. Navigate to the Split Tunneling tab and toggle the switch to enable the feature.
  4. Choose the split tunneling mode — Include or Exclude.
  5. Enter the addresses you wish to add, separating them with commas or spaces.
    • Include mode — enter the IP addresses and subnets that should be routed through the NordLayer tunnel (e.g., 10.10.0.0/20, 192.168.1.0/24). All other traffic will use the direct internet route.
    • Exclude mode — enter the IP addresses, subnets, or domains that should bypass the NordLayer tunnel (e.g., 203.0.113.0/24, example.com). All other traffic will be routed through the tunnel.
  6. Click Enable to submit changes.

How to enable split tunneling on a Browser Extension

  1. Navigate to Network and select Browser Extension.
  2. Open the Split Tunneling tab and toggle the switch to enable the feature.
  3. Enter the domains or wildcard patterns that should bypass the NordLayer tunnel (e.g., example.com, *.example.com). All other browser traffic will be routed through the tunnel.
  4. Click Enable to submit changes.
Note

Browser Extension split tunneling only supports the Exclude mode.

Supported app versions

Split tunneling is supported from the following NordLayer app versions, depending on the mode you are using:

Include Mode

  • Windows: 3.3.1
  • macOS: 3.3.0
  • Android: 4.4.0
  • iOS: 4.4.0
  • Linux: 3.3.0

Exclude Mode

  • Windows: 3.10.0
  • macOS: 3.11.0
  • iOS: 4.12.0
  • Linux: Coming soon
  • Android: Coming soon

Older app versions may have configuration issues.


Note: In case you have any questions or are experiencing any issues, please feel free to contact our 24/7 customer support team.