Domain-based (FQDN) Split Tunneling for Desktop and Mobile
Please add domain-based split tunneling (e.g., *.company.intern) to the Windows/macOS desktop clients, similar to how the browser extension already handles it.
The current IP- and App-based split tunneling is unreliable for modern web services with dynamic IPs/CDNs and internal corporate networks.
Solution: The client should monitor DNS queries for specified domains and dynamically route the resolved IPs. This would massively improve reliability and close a major feature gap compared to enterprise VPN clients.
Please add this feature for Desktop and Mobile App
-
NetGus
commented
I would really like to see Proton VPN implement true destination-based Split Tunneling, rather than limiting it primarily to applications.
The current application-based approach has a major limitation: sometimes I want an application to use the VPN, but I want specific destinations accessed by that application to bypass the VPN.
For example, my browser should work like this:
Internet websites → VPN
nas.example.com → direct connection
firewall.local → direct connection
Everything else → VPNWith the current application-based Split Tunneling, this isn't possible. I would have to exclude the entire browser from the VPN, which defeats the purpose of using the VPN for my normal web traffic.
The same issue exists with local network resources:
SMB shares on a NAS
NAS web interfaces
Firewall/router administration interfaces
SSH/RDP connections to local machines
Other internal web servicesWhat I would like to see is the ability to create Split Tunneling rules based on destination, for example:
Exclude from VPN:
192.168.1.0/24
10.0.0.0/8
nas.example.com
homeassistant.example.com
*.internal.example.comIdeally, Proton VPN could support:
FQDN / domain names
Wildcard domains
IPv4/IPv6 addresses
CIDR subnets
Optional port-based rulesThis would be much more flexible than application-based Split Tunneling because the same application could then access both VPN and non-VPN destinations.
Windscribe already provides a much closer implementation of this concept, which makes the difference particularly noticeable.
I really like Proton VPN, but for users managing their own NAS, firewall, Home Assistant, servers, or other local infrastructure, this limitation is significant.
Please consider adding destination/FQDN-based Split Tunneling. It would make Proton VPN considerably more useful for advanced users while allowing us to keep our normal Internet traffic protected by the VPN.