CyberGhost Split Tunneling on Mac: What Works in 2026

Split tunneling lets you pick which apps use the VPN and which connect directly. If you searched for how to do this with CyberGhost on a Mac, here is the honest answer: the macOS picture is different from Windows and Android — and there is a clean way to get real per-app routing regardless.

Does CyberGhost support split tunneling on macOS?

CyberGhost supports split tunneling on Android and Windows (via its Smart Rules / app rules). The macOS app does not include split tunneling — on a Mac, CyberGhost is a whole-device tunnel with no per-app exceptions.

Features change between releases, so double-check the current version of the CyberGhost app — but if per-app control is missing or limited on your Mac, you don't have to switch providers to get it.

Why most VPN apps skip split tunneling on the Mac

This isn't laziness on the provider's part. On Windows, a VPN can filter traffic per process with comparatively little friction. On macOS, deciding routes per app means shipping and maintaining a separate Network Extension that macOS treats as a transparent proxy — a substantial piece of engineering that most VPN vendors reserve for their Windows clients. The result: on the Mac, most VPN apps are all-or-nothing. Read the full explanation in How per-app VPN routing works on macOS.

How to get per-app routing with CyberGhost on your Mac

AppLanes adds the missing layer. It is not a VPN and never replaces CyberGhost — it sits alongside it and decides, per app, whether traffic goes through the tunnel CyberGhost creates, around it (direct), or is blocked entirely.

  1. Install AppLanes from the Mac App Store (3-day free trial, every feature unlocked, no account) and approve its network extension when macOS asks — see the setup FAQ if the prompt doesn't appear.
  2. Connect CyberGhost as you normally would.
  3. In AppLanes, set your default route — for example, everything through the VPN.
  4. Add per-app exceptions: switch any app to Direct to route it around CyberGhost, or to Block to cut its network access entirely.
  5. Changes apply to new connections instantly; apps holding old connections reconnect within seconds (or restart the app).

Tips for running AppLanes with CyberGhost

  • CyberGhost on macOS connects over WireGuard, OpenVPN, or IKEv2 — all standard tunnel types that AppLanes routes around or through per app.
  • If CyberGhost's own kill switch is set to block all traffic when the VPN drops, your Direct apps may lose connectivity during a drop too. AppLanes has its own per-app leak protection that only holds back VPN-routed apps — many users prefer that granularity.
  • Keep just one VPN connected at a time; with two tunnels up, "route through VPN" becomes ambiguous.

Frequently asked questions

Does AppLanes work with CyberGhost?

Yes. AppLanes works with any VPN that creates a standard tunnel on macOS, including CyberGhost. It routes traffic around or through whatever tunnel is active — no changes to your CyberGhost account or configuration are needed.

Do I need to stop using CyberGhost to use AppLanes?

No. AppLanes is not a VPN and carries no traffic to any server. You keep using CyberGhost exactly as before; AppLanes only decides which apps' connections enter the tunnel.

Get per-app VPN routing on your Mac

Every feature unlocked for 3 days, free — no account, works with any VPN, macOS 13+.

Keep reading