Home/Blog/local network access
New in ROOT VPN · No activity logs
Turn on a VPN and your printer, NAS and Chromecast can suddenly vanish, because every connection is being sent down the tunnel. ROOT's Allow LAN setting keeps those local devices reachable while everything else stays encrypted.
A full-tunnel VPN, which is what you want most of the time, routes every connection through the encrypted tunnel to the exit server. That is great for privacy, but it also means requests to devices on your own network, addressed in private ranges like 192.168.x.x, get sent to the VPN instead of across the room.
The result is that your printer stops responding, your NAS drops off, and casting to a Chromecast or reaching a game console fails, all while the VPN is on. Nothing is broken; the traffic is simply going the wrong way.
Allow LAN tells ROOT to leave your local network out of the tunnel. Traffic to private and link-local addresses goes straight across your LAN as it normally would, while everything bound for the internet still travels through the encrypted VPN.
It is a precise carve-out, not an all-or-nothing switch. ROOT excludes exactly the private, link-local and multicast ranges that local devices use, and keeps DNS working through the tunnel, so you keep full VPN protection for your browsing and only your own network becomes reachable again.
Switch Allow LAN on when you need to print at home, reach a NAS, cast to a TV, control smart-home gear, or connect to a console or PC on the same network while the VPN is running. For most people at home, leaving it on is convenient and safe.
Leave it off when you are on a network you do not trust, like public café or hotel Wi-Fi. On those networks you generally do not want to be reachable by, or reach out to, other machines nearby, so the stricter full-tunnel behaviour with the kill-switch is the safer default.
Read more about what ROOT can do, or browse every post.
Create a free account, flip on Allow LAN, and use the VPN and your local network together.
Get ROOT VPN, free