How to use app-level smart routing: send only the apps you need through the VPN

What app-level smart routing is
App-level smart routing is a setting that sends only the network requests of the apps you choose through the VPN, while all other apps keep using your local network directly. Once it’s on, your device has two paths: apps on the routing list go out through the VPN exit, and apps not on the list use the local network as usual.
It mainly addresses two problems that come with sending all traffic through the VPN. First, local services, LAN devices and online banking, which don’t need a proxy, get affected along with everything else. Second, under pay-by-data billing, traffic that doesn’t need a proxy still uses up the capacity you bought.
When to turn routing on
The situations below come up often. If any one of them matches yours, app-level routing is worth trying first.
- Only a few apps need an exit in a specific region, such as a browser, a development tool or a particular client;
- You need to reach devices on your LAN or local services, such as a printer, a NAS or a development environment running on your machine;
- You want tighter control over data use, so that unrelated programs such as background updates and file syncing don’t use up the capacity you bought;
- You would rather keep online banking, payment and similar apps on your local network, so the exit region doesn’t change while you use them.
How to decide which apps go on the routing list
Before you set up routing, spend a few minutes sorting the apps you use into two groups: those that need the VPN and those that don’t. The test is simple: does the service this app connects to need an exit in a specific region?
Apps to consider adding to the list
Browsers that need an exit in a specific region, clients for AI tools, and development and debugging tools that reach overseas services usually belong here. What they have in common is that on the local network they either can’t connect or show content that doesn’t match the target region.
Apps that can stay on a direct connection
Domestic video, music and social apps, local databases and development services, and shared folders and printers on your LAN generally don’t need to go through the VPN. Keeping them direct means they aren’t affected by a change of exit and don’t use data for nothing.
Start small, then add more
For your first setup, add only the one or two apps you rely on, and once they work normally, add others one at a time. That way, if an app has a problem, it’s easy to tell which change caused it.
A complete setup example
Take a developer who uses a browser, a code editor and a local database every day. The browser needs to open pages from a specific region, the code editor needs to pull extensions and dependencies from overseas, and the local database and debugging services run only on the machine itself.
Following the method above, add the browser and the code editor to the routing list and leave the local database on a direct connection. When that’s done, check three things: whether the browser opens the target pages, whether the editor pulls dependencies normally, and whether the local services can still be reached as usual. If all three pass, the routing setup is done. Later, if you add a tool that needs a specific exit, add it to the list; there’s no need to redo the whole setup.
A routing list isn’t something you set once and leave. When you change tools or the way you work, the list should change with them. Looking at the list every so often and removing apps you no longer use helps you avoid unnecessary data use.
How routing helps you control data
AnBo is billed by data plan, and once the data is used up you need to buy more, so which traffic goes through the VPN directly decides how long your capacity lasts. App-level routing keeps local apps outside the VPN, so the capacity you buy stays closer to what you actually need.
| Scenario | Suggestion | Why |
|---|---|---|
| A browser opening pages that need a specific region | Add to the routing list | This is the core task that needs the exit |
| A development tool pulling overseas dependencies | Add to the routing list | A direct connection may fail to connect, or may be unstable |
| Local databases, LAN devices | Keep direct | No proxy needed, and going through the VPN may stop them connecting |
| Large file syncing, system updates | Keep direct | They use a lot of data and usually don’t need a specific exit |
To see how much routing actually saves, compare the same set of tasks twice: once with everything going through the VPN and once with only the necessary apps going through it, noting the change in your account’s usage each time. The bigger the difference, the more data was being used unnecessarily before.
One more point to know up front: routing only decides which traffic goes through the VPN. It doesn’t change the speed of the VPN exit itself. If you don’t see a speed change after setting it up, that’s normal.
Common questions
What if an app on the routing list still can’t connect?
First confirm that the service the app connects to is itself available, then consider whether other processes of the app are also sending requests. Some apps start helper processes, and if you handle only the main program, some requests may still go out over the local network. In that case, you can use TUN mode to cover them.
Is it better to put more apps on the routing list?
No. The more apps on the list, the more data is used and the more the local network is affected. Keeping only the apps that actually need a specific exit is the safer approach. If you find yourself wanting to add most of your apps, the way you use this device is closer to “everything through the VPN,” and you can consider TUN mode directly instead of continually extending the routing list.
Do I still need to choose a region after turning on routing?
Routing decides which apps use the VPN; the exit region is still determined by the exit you choose. The two are separate: choose the exit first, then decide which apps use it.
What to do when routing isn’t enough
App-level routing depends on being able to tell which app a request comes from. Command-line tools, subprocesses in development environments and tasks involving virtual machines sometimes can’t be added to the routing list individually. In those cases, consider turning on TUN mode, which sends more system-level network requests through the VPN. For when it applies and what to check before using it, see this guide: When to use TUN mode.


