Skip to content

Routing modes

VPN Bypass has three modes. Switch from the dropdown's Mode switch or from the Mode menu at the right end of the Settings title bar. Both ask before they switch, because the mode changes how all traffic is routed. The dropdown asks with an alert. Settings opens a sheet that explains each mode and says what your lists hold for it.

The three modes

  • Bypass (default): everything uses the VPN as usual, and only the domains/services you list are routed around it to your regular connection. Best when your VPN carries all traffic but a few apps misbehave through it.
  • VPN Only: the inverse: your regular connection is the default, and only the domains/services you list are forced through the VPN. Best for a mostly-direct machine with a few things tunneled.
  • Custom: a per-rule engine: you define routes (egresses) and rules that map traffic to them. Rules are evaluated top-to-bottom, first match wins, with a pinned "everything else → default" rule. This is what unlocks multi-VPN, proxy, and Tailscale-peer routing.

Bypass and VPN Only work exactly as they did in earlier versions — if that's all you need, nothing changes. Custom mode is entirely opt-in.

Routes and rules (Custom mode)

A route is a place traffic can exit:

Route type Traffic exits via
Direct your local gateway (around the VPN)
VPN a specific VPN interface — pick which tunnel when several are up (multi-VPN)
HTTP / SOCKS5 proxy a local 127.0.0.1 listener that forwards to your proxy
Tailscale peer out through a chosen Tailscale device used as an exit

A rule maps traffic to a route by domain, suffix, ip, cidr, service, or process. The first matching rule wins; anything unmatched takes the default route. Direct and detected VPN routes appear automatically; proxy and Tailscale-peer routes are ones you add.

A proxy route's 127.0.0.1 listener holds your upstream proxy credentials, so it will not serve a client that cannot prove it is you. Any process on the machine can reach a loopback port, and macOS gives a TCP listener no way to see who connected, so the listener asks for a password instead. Use Copy Shell Exports or Copy Proxy URL on the route. Both hand you the address with the credentials already in it:

export HTTPS_PROXY="http://vpnb:<secret>@127.0.0.1:18042"

The secret is generated once and kept in the app's config file, which only your account can read. Copy them again if you ever reset your config. A browser takes 127.0.0.1 and the port in its proxy settings and then asks you to sign in: the user is vpnb, and the password is the part between vpnb: and @ in the copied proxy URL.