--- title: "How to enable split tunneling via the Control Panel" slug: "enable-ip-based-split-tunneling" description: "Learn how to request split tunneling through the Control Panel. This guide provides clear instructions to help you efficiently set up split tunneling." updated: 2026-07-29T10:53:49Z published: 2026-07-29T10:53:49Z canonical: "help.nordlayer.com/enable-ip-based-split-tunneling" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt > Use this file to discover all available pages before exploring further. # How to enable split tunneling via the Control Panel NordLayer allows you to customize your internet traffic routing with split tunneling. There are two split tunneling modes: - **Include** — only the specified addresses are encrypted and routed through the NordLayer tunnel. All other traffic uses the direct internet route. - **Exclude** — all traffic is encrypted and routed through the NordLayer tunnel except for the specified addresses, which bypass the tunnel and use the direct internet route. Note Split tunneling only impacts the flow of IP traffic. DNS requests are still resolved by the gateway and are subject to DNS filtering and Web Protection policies. ### Where each mode is available - **Include** mode can be enabled on a Gateway. - **Exclude** mode can be enabled on a Gateway or a Browser Extension. Each mode supports different address types (up to 100 entries): - **Gateway — Include** supports IP addresses and subnets. - **Gateway — Exclude** supports IP addresses, subnets, and domains/subdomains. - **Browser Extension — Exclude** supports domains/subdomains and wildcards. ### How to enable split tunneling on a Gateway 1. Navigate to **Network** and select **Gateways**. 2. Select the gateway you want to configure and click on it. 3. Navigate to the **Split Tunneling** tab and toggle the switch to enable the feature. 4. Choose the split tunneling mode — **Include** or **Exclude**. 5. Enter the addresses you wish to add, separating them with commas or spaces. - **Include** mode — enter the IP addresses and subnets that should be routed through the NordLayer tunnel (e.g., `10.10.0.0/20`, `192.168.1.0/24`). All other traffic will use the direct internet route. - **Exclude** mode — enter the IP addresses, subnets, or domains that should bypass the NordLayer tunnel (e.g., `203.0.113.0/24`, `example.com`). All other traffic will be routed through the tunnel. 6. Click **Enable** to submit changes. ### How to enable split tunneling on a Browser Extension 1. Navigate to **Network** and select **Browser Extension**. 2. Open the **Split Tunneling** tab and toggle the switch to enable the feature. 3. Enter the domains or wildcard patterns that should bypass the NordLayer tunnel (e.g., `example.com`, `*.example.com`). All other browser traffic will be routed through the tunnel. 4. Click **Enable** to submit changes. Note Browser Extension split tunneling only supports the **Exclude** mode. ## Supported app versions Split tunneling is supported from the following NordLayer app versions, depending on the mode you are using: **Include Mode** - **Windows**: 3.3.1 - **macOS**: 3.3.0 - **Android**: 4.4.0 - **iOS**: 4.4.0 - **Linux**: 3.3.0 **Exclude Mode** - **Windows**: 3.10.0 - **macOS**: 3.11.0 - **iOS**: 4.12.0 - **Linux**: Coming soon - **Android**: Coming soon Older app versions may have configuration issues. --- **Note**: In case you have any questions or are experiencing any issues, please feel free to contact our [24/7 customer support team](/docs/how-do-i-contact-nordlayer-customer-support).