Lvcha VPN split tunneling works when browsers, maps, and video sit in the tunnel, while banks, campus clients, and corporate mail stay direct. Prove the node in global mode first, then change one app at a time.

Per-app mode is how phones fake a healthy VPN. Miss the system browser and the client still says Connected while Chrome uses the hotel resolver. Finish install and permission before you draw lists.

Global first

If global cannot browse, stop editing lists and open the no-traffic guide. When global works, switch back to per-app and compare a checked browser with an unchecked local app.

A practical allow/deny table

TypeDefaultWhy
Chrome / Safari / WebViewTunnelOtherwise egress and DNS disagree
Banking and government appsDirectRisk engines watch region hops
Work mailUsually directIP allow lists
Video appsAs neededCatalog work belongs in the streaming article

Android sometimes forgets downloaders that embed their own WebView. If a skin-browser fails, tick the real engine too. iOS per-app controls are weaker—use smart split or global rather than assuming the client is broken. Platform notes: guides.

Change one checkbox

Editing DNS, Kill Switch, and five apps together makes the next failure un-debuggable. After each change, do one concrete action: refresh mail, play thirty seconds of video. Fail? Revert that one line.

Split tunneling does not own Windows PAC or a second VPN. Clear those as in stacked proxies. Keep a note of the working list for the next reinstall from the download page. Permission leftovers: FAQ.

Field questions tied to this guide

  • Per-app vs smart split? Per-app is a process list. Smart split is domain/IP rules. Phones are easier with per-app. On Windows, do not exclude the same browser twice.
  • Should chat apps enter the tunnel? Keep messaging direct if it is stable. If only the in-app browser fails, add the app once, test, revert if worse.
  • Connected, but Chrome’s IP never changes. Chrome or WebView is not on the list. Add both.
  • Work mail dies in the tunnel. Many tenants allow only office IPs. Exclude the mail app or use global only when you need the external net.

Change one control, then retest

While working through “Lvcha VPN per-app split tunneling: what belongs in the tunnel”, write the download-page version, mode, protocol, and node name on the first line of a note. After each toggle, run one check only: 1.1.1.1/help or the exact page that failed. Changing Kill Switch, split rules, and nodes together makes the next failure un-debuggable. Get Lvcha VPN packages only from the download page; permissions and device limits live in the FAQ and guides.

On office or hotel networks, finish captive portals and clear leftover PAC entries before you decide this article’s failure mode applies. A cellular A/B exposes router DNS and parental filters quickly. Avoid hammering login on a second device during the test so session kickouts are not mistaken for radio drops.

Pin the combination that works—SSID, node, protocol—and reuse it on that network instead of starting from Auto every time. Keeping slug lvcha-split-tunnel-guide as your note title makes the write-up searchable later.

When to stop and change layers

After five identical failures, stop. Recheck the documented build, confirm a single tunnel client, ensure Kill Switch was not blocking a portal, and verify the browser is not Direct in a split list. Stopping is how you escape the wrong layer.

When you ask for help, include time, SSID, mode, protocol, node names, and steps already tried. After recovery, verify egress in a clean browser so cache does not fake success, then write the split list or favorites back into your notes before the next reinstall.

Extra pass for “Lvcha VPN per-app split tunneling: what belongs in the tunnel”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Lvcha VPN.

Extra pass for “Lvcha VPN per-app split tunneling: what belongs in the tunnel”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Lvcha VPN.