When configuring KuaiLian split tunneling or a bypass list, open whatever your build labels as split / smart split / bypass / app exclude / domestic direct, then test two traffic classes on the same device: destinations that should use the proxy and ones that should stay direct. If a domestic site enters the tunnel—or an app you need proxied sits on the exclude list—fix the list and reconnect before you burn time switching nodes.
A coworker added banking and payments to bypass, and the meeting docs app got swept in too. The VPN icon stayed on; the foreign docs site kept timing out. He thought the network was dead. The tunnel was fine—those packages were simply kicked out of it. Mis-split traffic feels like “the wrong path,” which is different from every site failing at once.
If you are connected but almost nothing loads, start with connected but no internet (DNS, nodes, system proxy). If you cannot connect at all, see connection troubleshooting. Disconnect leaks or false offline cuts from the network lock: Kill Switch. This article is only for split configuration checks—no streaming unlock or node-speed claims.
Split rules vs “connected but no internet”
- Connected, nothing loads: browser and most apps fail → DNS / node / system proxy first
- Mis-split: domestic sites feel wrong in the tunnel, or one app that should proxy behaves like direct → bypass list and app exclude
- Just slow: pages open but latency is high → use the slow-speed guide; stop adding/removing list entries at random
Write down the symptom before you edit: one app, or a whole class of domestic domains. Re-test the same scenario after each change.
Find the real menu names in your build
Labels differ by version. Look for split mode, smart split, bypass list, app exclude / per-app proxy, or domestic direct. Use what you see on the device—not a screenshot from another phone.
1. Snapshot the current mode
Global, smart/split, or allow-list only—note it so you can roll back.
2. Open bypass / exclude
Lists may be domains, ranges, or app checkboxes. Count selected rows before editing.
3. Read domestic-direct carefully
It may mean “matched domestic rules go local” or something broader. The semantics are not universal.
4. Change one class at a time
Do not flip global, clear the list, and switch protocol together—you will not know what fixed it.
Domestic direct: should proxy, but goes direct
Foreign docs, mail, or dev tools time out or land on the wrong region page while the VPN icon is on. Suspect a domestic-direct / smart rule sending that host local before you cycle nodes.
- Turn domestic direct off or switch to global—test only that destination
- If global works immediately, the fault is the split rule, not login
- Return to smart/split and check whether the domain or app is on the bypass list
- Remove it, reconnect, and hit the same URL again
Keep device and network fixed. On a locked-down office Wi-Fi, VPN-off may also fail—that is policy, not a broken toggle.
Bypass list and app exclude: should stay direct, but tunnels
Banking, payments, and local lifestyle apps dragged into the tunnel often show OTP delays, risk prompts, or sluggish domestic pages. Explicitly exclude them; do not wait for “smart” to guess right.
- Tick the real app in exclude; dual-app or renamed packages may not match after reinstall
- For domain bypass, list only hosts you verified need direct—over-broad wildcards kick unrelated traffic out of the tunnel
- Reconnect after edits; some OSes need the app force-closed before new routes apply
Verify both sides: the excluded app should feel closer to VPN-off on domestic sites, while a non-excluded browser tab still reaches a site that needs the tunnel. If both sides fail, move to connected but no internet.
Global contrast: prove the rule took effect
Without a before/after test, list edits are noise. Run three checks:
- A domestic site (portal or bank login): when meant to be direct, it should not feel routed far away
- A destination that needs the proxy: it should open under global / non-bypassed mode
- One excluded app: behavior should approach VPN-off
If the client shows a mode badge, confirm it still matches what you think you set. Quit system proxies and other VPN clients while testing so exclusions are not overridden.
Common misconfigs (match yours, then edit)
- Tools that need the proxy sitting on the bypass list—“VPN on” but acts like direct fail
- Domestic direct enabled while assuming every foreign hop still forces the tunnel
- Exclude ticked on an old dual-app icon; the instance you open still tunnels
- List changed without reconnect; routes stay stale
- Clash, system proxy, or a second VPN covering the exclude rules
Login or auth errors belong in login / auth troubleshooting—do not “fix” passwords by editing split lists.
Still wrong: what to record before FAQ / download
If contrast tests still fail, gather this for FAQ or in-app support:
- Device, OS, KuaiLian version, and install source
- Mode (global / split) and domestic-direct on/off
- Which apps or domains are bypassed (never send passwords)
- Which class failed: should-proxy-but-direct, or should-direct-but-tunneled
If menus do not match older screenshots, check the download page before reinstalling. Reinstall can clear a bad config; it does not guarantee speed or unlocks. Setup paths: Guides.