How it works¶
Supported VPN types¶
| VPN Client | Detection |
|---|---|
| GlobalProtect | ✅ Full |
| Cisco AnyConnect | ✅ Full |
| OpenVPN | ✅ Full |
| WireGuard | ✅ Full |
| Fortinet FortiClient | ✅ Full |
| Zscaler | ✅ Full |
| Cloudflare WARP | ✅ Full |
| Pulse Secure | ✅ Full |
| Check Point | ✅ Full |
| Tailscale (exit node) | ✅ Full |
| Tailscale (mesh only) | ❌ Not VPN |
Steps¶
- VPN Detection: Monitors network interfaces and running processes to detect VPN type
- Gateway Detection: Identifies your local gateway (Wi-Fi/Ethernet router)
- Route Management: A small privileged helper adds/removes host routes to steer traffic per your mode — around the VPN (Bypass), through it (VPN Only), or to the route a rule selects (Custom). The helper is cdhash-pinned to this app and uses no Network Extension entitlements.
- Route Verification: Pings up to 10 routed single addresses (ping cannot test a range) to check they answer, after an apply when that option is on or when the apply had failures, or from Verify Routes in the menu
- DNS Bypass: Optionally adds entries to
/etc/hoststo bypass VPN DNS
VPN Detection Logic¶
Running more than one VPN (e.g. a corporate client plus Tailscale), or local proxies? See Coexistence with other VPNs and proxies for exactly what VPN Bypass will and will not touch — one tunnel is acted on, Tailscale is never selected, loopback is never routed.
The app intelligently detects corporate VPNs while avoiding false positives:
| Interface Type | IP Range | Detection |
|---|---|---|
| Corporate VPN (GlobalProtect, Cisco, etc.) | 10.x.x.x, 172.16-31.x.x |
✅ Detected as VPN |
| Cloudflare WARP | 100.96-111.x.x |
✅ Detected as VPN |
| Tailscale (mesh networking) | 100.64-127.x.x |
❌ Not detected* |
| Tailscale (exit node active) | 100.64-127.x.x |
✅ Detected as VPN |
*Tailscale in normal mode only routes traffic to other Tailscale devices. It's not a "full VPN" because your regular internet traffic still goes through your normal connection. The app only considers Tailscale as a VPN when you're using an exit node (routing all traffic through another Tailscale device).
The detection also requires:
- The interface must have the UP flag (actually connected, not just configured)
- The interface must have an IPv4 address in a VPN range