How to Set Up Split Tunneling on Android
14 min read
Learn how to configure split tunneling on Android so only selected apps use your VPN, keeping other traffic on your regular network.
September 27, 2026 12:30
Many Android users run a VPN for privacy, streaming, or corporate access, but a full‑device VPN can slow down local services, increase data usage, or block certain apps that don’t need protection. Split tunneling lets you choose which apps go through the VPN while the rest use your normal internet connection.
What you’ll get: After following this guide you’ll have a working per‑app VPN configuration, understand the trade‑offs, and know how to troubleshoot common issues.
Before you start
- Make sure your device is charged to at least 50 % or plugged in.
- Connect to a stable Wi‑Fi or mobile network – you’ll need internet access to download VPN profiles.
- Identify the apps you want to protect. Write down their package names (e.g.,
com.netflix.mediaclient) – you’ll need them later.
- Back up important data. Changing VPN settings rarely corrupts data, but a full device reset may be required if something goes wrong.
Understanding Android’s split‑tunneling options
Android itself does not expose a universal split‑tunneling UI, but three practical paths exist:
- Per‑app VPN via Work Profile (Android 9+) – the system lets a device‑owner app (often a corporate VPN) decide which apps use the VPN.
- Third‑party VPN apps with built‑in split tunneling – WireGuard, OpenVPN Connect, and many commercial VPNs include a per‑app selection screen.
- OEM‑specific features – Some manufacturers (e.g., OnePlus, Xiaomi) add a “App VPN” or “Split tunneling” toggle in their settings.
This tutorial covers the first two methods because they work on any stock Android device.
Method 1 – Using a Work Profile (Android 9 and later)
A Work Profile isolates apps and data from the personal side of the phone. When you set a VPN as the “Work profile VPN,” only apps installed in that profile will route through it. This is the most reliable way to achieve split tunneling without third‑party software.
Step 1 – Create a Work Profile (if you don’t already have one)
- Open Settings → Accounts → Work profile (or Users & accounts → Work profile on some devices).
- Tap Set up work profile and follow the on‑screen prompts. You may be asked to sign in with a Google Workspace account; you can also create a temporary “dummy” account solely for the profile.
- After the profile is created, you’ll see a new app drawer with a briefcase badge indicating the work side.
Why this matters: Only apps installed inside the work profile can be forced to use a VPN, leaving the rest of the device untouched.
Step 2 – Install the VPN app inside the Work Profile
- Open the Play Store inside the work profile (it has a briefcase icon).
- Search for your VPN (e.g., WireGuard or OpenVPN Connect) and install it.
- Launch the VPN app and import or create the VPN profile you wish to use.
Tip: Keep the VPN app on the personal side as well if you occasionally need full‑device protection – you can switch between profiles later.
Step 3 – Enable the VPN for the Work Profile only
- Go to Settings → Network & internet → VPN.
- Find the VPN you just installed (it will show a small briefcase next to its name).
- Tap the gear icon next to the VPN and select Always-on VPN → Work profile only (or similar wording).
- Confirm the prompt that the VPN will be active whenever the work profile is unlocked.
Now any app you install inside the work profile will automatically use the VPN, while apps on the personal side will use your normal network.
Step 4 – Move the apps you want protected into the Work Profile
- Open the Settings app → Apps & notifications → App info.
- Select an app you wish to protect (e.g., Netflix).
- Tap Move to work profile. If the option is greyed out, the app may not support work profile installation; you’ll need to uninstall and reinstall it from the work‑profile Play Store.
- Repeat for each app you want routed through the VPN.
Result: Those apps now appear in the work‑profile app drawer and will send all traffic through the VPN.
Method 2 – Using a VPN app that supports per‑app split tunneling
If you prefer not to create a work profile, many modern VPN clients let you pick apps directly. The steps below use WireGuard as an example because it’s open source, lightweight, and offers a clear per‑app UI. The process is similar for OpenVPN Connect or commercial VPNs that expose a “Split tunneling” option.
Step 1 – Install WireGuard (or your chosen VPN) from the Play Store
- Open Google Play Store → search
WireGuard → tap Install.
- Launch the app once installation finishes.
Why WireGuard? It uses modern cryptography, has a tiny footprint, and its UI makes per‑app selection obvious.
Step 2 – Import or create a VPN tunnel
- In WireGuard, tap the + button → Create from QR code / file or Add empty tunnel if you configure manually.
- Enter the required fields (private key, public key, endpoint, allowed IPs). If you have a configuration file from your VPN provider, import it directly.
- Save the tunnel and give it a recognizable name (e.g., “MyWorkVPN”).
At this point you can enable the tunnel with the toggle switch to verify connectivity.
Step 3 – Enable per‑app split tunneling
- Open the tunnel you just created by tapping its name.
- Scroll down to the Allowed apps section.
- Tap Add app and select each app you want to protect. The UI may list apps by their friendly name; you can also search by package name.
- After adding all desired apps, exit the settings screen.
What happens behind the scenes: WireGuard creates a virtual network interface and adds routing rules that direct traffic from the selected apps through that interface, leaving other apps untouched.
Step 4 – Activate the tunnel
- Return to the main WireGuard screen and toggle the switch next to your tunnel name.
- Watch the connection log – a green checkmark means the tunnel is up.
- Open one of the protected apps and verify its IP address (e.g., by visiting
https://ifconfig.me). It should show the VPN’s public IP.
- Open a non‑protected app (like your default browser) and check the IP again – it should show your regular ISP address.
If the IP addresses match the expected outcome, split tunneling is working.
Alternative: Using a commercial VPN with built‑in split tunneling
Many paid VPN services (e.g., NordVPN, ExpressVPN, Surfshark) add a “Split tunneling” screen in their Android app. The workflow is usually:
- Install the provider’s app from the Play Store.
- Log in and connect to a server.
- Open the app’s Settings → Split tunneling (or App exclusions).
- Select apps to exclude from the VPN or apps to force through it, depending on the UI.
- Save and reconnect.
Because the UI varies, consult the provider’s help page for exact wording. The advantage is a single‑click solution and automatic updates.
Troubleshooting common issues
1. Apps still use the regular network
- Check the routing rules – on WireGuard, open the tunnel details and confirm the selected apps appear under
Allowed apps.
- Restart the app – some apps cache network routes on launch. Close it from Recents and reopen.
- Verify VPN is active – the system status bar should show the VPN icon. If not, toggle the tunnel off/on.
2. VPN disconnects when the protected app goes to background
Android may stop “always‑on” VPN for battery saving. To prevent this, enable Always‑on VPN in Settings → Network & internet → VPN → [Your VPN] → Always‑on VPN. Note that some VPN apps override this setting; consult the app’s documentation.
3. DNS leaks on non‑protected apps
When only some apps use the VPN, the system DNS resolver may still use the VPN’s DNS for all apps, causing leaks. To avoid this:
- In WireGuard, add
DNS = 1.1.1.1, 8.8.8.8 under the [Interface] section – this forces DNS for the tunnel only.
- On devices with Android 10+, go to Settings → Network & internet → Private DNS and set it to
off if you rely solely on the VPN’s DNS.
4. Work Profile not available on your device
Some OEMs hide the work profile feature on consumer‑grade devices. In that case, fall back to Method 2 (per‑app VPN apps) or consider installing the open‑source “Island” app, which creates a sandbox similar to a work profile without needing enterprise enrollment.
Safety and privacy considerations
- Data leakage: Split tunneling defeats the purpose of a full‑device VPN for apps you forget to add. Periodically review the allowed‑apps list.
- Legal compliance: Some corporate policies forbid split tunneling because it can expose internal traffic. Ensure you have permission before configuring a work‑profile VPN.
- Battery impact: Running two network stacks simultaneously can increase power draw. Monitor battery usage in
Settings → Battery → Battery usage after setup.
Wrap‑up
Split tunneling on Android is achievable through a work profile, a VPN client with per‑app routing, or OEM‑specific settings. By following the steps above you can protect sensitive apps, keep local services fast, and retain control over your data flow. Remember to test each protected app, keep your VPN configuration up to date, and revisit the allowed‑apps list whenever you install new software.