> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/2.2/features/wireguard/create-your-vpn-network/split-tunnel-configuration.md).

# Split Tunnel Configuration

To configure split tunnel routing, you need to add the networks that should always route through your VPN connection to the[ Allowed IPs configuration in the VPN Location](/2.2/features/wireguard/create-your-vpn-network.md#allowed-ips). You can do this either in the wizard during the location configuration, or by navigating to Locations, clicking on the "..." menu, and selecting "Edit":

<figure><img src="https://content.gitbook.com/content/pE5yODhpiy5pT1XxY0BS/blobs/v3YRBqcY2ZnUVfSNeGxa/Screenshot%202026-05-22%20at%2021.53.11.png" alt="" width="302"><figcaption></figcaption></figure>

And then define the networks in Allowed IPs:

<figure><img src="https://content.gitbook.com/content/pE5yODhpiy5pT1XxY0BS/blobs/XJ32gzgfmDloIvwPJzVL/Screenshot%202026-05-22%20at%2021.52.17.png" alt=""><figcaption></figcaption></figure>

Now any time a user connects to VPN with Predefined Traffic option:

<figure><img src="https://content.gitbook.com/content/pE5yODhpiy5pT1XxY0BS/blobs/Nu1Qv7UyrhZ8nTBYmtqB/predefined-traffic-marked.png" alt="" width="563"><figcaption></figcaption></figure>

traffic to those networks will go through the VPN, and all other traffic will use the user's default router or internet connection.
