Analyzing your connection...
Checking your IP address...

Introducing Geo Exclusion for NymVPN

Route traffic for selected regions outside the VPN tunnel, so local apps work at full speed while everything else stays protected

6 mins read
NymVPN 1-click connect.png
Share

If you live in a country that censors the internet, you know the other problem: Your banking app won't open because the connection comes from abroad. A government portal times out. Local news is suddenly blocked. These services expect a local connection, and a VPN gives them a foreign one.

The usual workaround is to disconnect. That fixes the local service, but it leaves you unprotected everywhere.

Geo Exclusion on NymVPN gives you a different route. Traffic to a selected region leaves the VPN tunnel and connects directly at full local speed, while everything else stays inside the tunnel. You keep protection where you need it and lose the friction where you don't want it.

Important to know about Geo Exclusion

  • It's a beta feature and still in active development
  • This is an advanced setting that requires configuring a proxy on your device or app outside of NymVPN
  • It requires that your browser, app, or device has SOCKS5 proxy support
  • It's currently only available for IPs in China, with more countries to come
  • It's best used for browsers on desktop macOS, Windows, or Linux
  • It's not yet available on iOS

How Geo Exclusion works

Inside the app, two things change when you switch it on.

  1. NymVPN starts a local SOCKS5 proxy and places it outside the VPN tunnel. That is what lets you connect directly while the VPN is running.

  2. Any web request you point at that proxy is sorted by destination: excluded regions go direct, everything else goes through the VPN tunnel.

The VPN tunnel itself doesn't change, and neither does anything you haven't pointed at the proxy. That is why setup takes two steps: the switch prepares the route, pointing an app at it puts traffic on it.

This is split tunneling applied to a region rather than an app. Split tunneling sends a whole app outside the tunnel; Geo Exclusion divides one app's traffic by destination. That is what makes it work for a web browser, where a few destinations are local and most are not.

The app lists the excluded regions available and how many IP ranges each covers, so you can see the scope of what leaves the tunnel.

Getting it working takes 3 steps

First, NymVPN needs to be connected: the SOCKS5 proxy doesn't run without it. Then two things have to happen:

  1. Connect NymVPN normally. You need an active NymVPN connection running.
  2. Turn on Geo Exclusion. Enable Geo Exclusion in NymVPN Settings and copy the SOCKS5 port (1081) and address (127.0.0.1) listed in the app.
  3. Set up the proxy in your browser. Enter that port and address in your browser's proxy settings.

The toggle alone changes nothing with (1) and (2). Traffic only leaves the tunnel once something points at the proxy.

Step 1: Turning on Geo Exclusion and copying the port

Geo Exclusion is off until you enable it.

  1. Open Settings in NymVPN.
  2. Click Geo Exclusion, directly below split tunneling.
  3. Toggle on Enable Geo Exclusion.
  4. Copy the SOCKS5 port (1081) and address (127.0.0.1) shown in that section.

⚠️ Copy these values rather than typing them. If you use a Chinese, Japanese, or Korean input method, typing 127.0.0.1 can produce full-width punctuation — 127。0。0。1 — which looks correct but will not work. The same applies to the digits in the port.

Step 2: Setting up your browser

Browser

Own SOCKS5 settings

What to do

Firefox

Yes

Configure it directly, see below

Mullvad Browser

Yes

Configure it directly, see below. It will not pick up a system proxy

Chrome, Edge, Brave

No

Use the system proxy: fine on macOS, needs a third-party client on Windows

Safari

No

Use the system proxy on macOS, or third-party extension on other OS

NymVPN.png

Geo Exclusion and SOCKS5 proxies: FAQs

Try again before changing anything. The connection to the Nym network is established when the first request arrives, not when you switch the feature on, and on a restricted network that can take several attempts. Reload a few times and give it a minute. If it still fails, reconnect NymVPN: switching Geo Exclusion on while the VPN is already connected can need a reconnect before the new routing takes effect.

Suspect DNS. When lookups resolve through the tunnel, a local domain can return an address hosted overseas, which then falls outside the excluded ranges and travels through the tunnel exactly as designed. The Proxy DNS when using SOCKS v5 setting prevents that.

It is the loopback address, and it always means "this device." The field is called Server on macOS and SOCKS Host in Firefox, but it points nowhere on the internet: it points back at NymVPN running on your own machine. The port then says which program to reach, and NymVPN's SOCKS5 proxy is the one listening on it.

No. That refers to sites you visit at those addresses, not to the proxy itself, so entering 127.0.0.1 as the SOCKS Host is correct. Leave No proxy for empty, though: anything listed there skips the proxy and travels through the VPN tunnel instead, which is the opposite of what you want.

The proxy stops running with it, and anything you pointed at that proxy will stop connecting until you turn the feature back on.

No. It keeps its own connection settings and will not inherit a system-wide proxy, so it has to be configured in the browser even if you have set one up for the rest of your device.

On macOS, yes: open System Settings, then Network, select Details beside your active connection, click Proxies, turn on SOCKS5 proxy, and enter 127.0.0.1 with your port, leaving the authentication fields blank. That covers every app, including Safari, Chrome, Edge, and Brave.

Windows and Linux have no usable system-wide SOCKS5 setting: Windows needs a third-party proxy client, and on Linux proxychains-ng will launch individual programs through the proxy. On both, configuring Firefox directly is simpler and costs little.

About the authors

App-Icon-32x32-retina.svg

Nym Core Team

Nym team
These posts are published by the core team behind NymVPN and the Nym mixnet.

New low prices

The world's most private VPN

Try NymVPN for free

Keep Reading...

Nym Connection Blog Image

Split tunneling with a VPN

Split tunneling gives users flexibility and efficiency when using a VPN, but with security risks. Mixnets provide a third option.

10 mins read
Mixnet Tuning on NymVPN.png

Introducing Mixnet Tuning in NymVPN

How NymVPN's new controls let you balance speed and anonymity on the Noise Generating Mixnet

3 mins read
aaaaaa.png

Nym’s roadmap for 2026: Unlocking the power of decentralization

Revitalizing the $NYM token, improving the mixnet, and taking decentralization to the limit

11 mins read
NymVPN anti-censorship.png

Nym is building a private internet without walls

NymVPN’s 2026 roadmap for censorship resistance and resilient online privacy for all

8 mins read