Home/Blog/local network access

New in ROOT VPN · No activity logs

Local network access stay on the VPN, still reach your devices

Turn on a VPN and your printer, NAS and Chromecast can suddenly vanish, because every connection is being sent down the tunnel. ROOT's Allow LAN setting keeps those local devices reachable while everything else stays encrypted.

Allow LAN: use your VPN and local devices at the same time

Why local devices disappear on a VPN

A full-tunnel VPN, which is what you want most of the time, routes every connection through the encrypted tunnel to the exit server. That is great for privacy, but it also means requests to devices on your own network, addressed in private ranges like 192.168.x.x, get sent to the VPN instead of across the room.

The result is that your printer stops responding, your NAS drops off, and casting to a Chromecast or reaching a game console fails, all while the VPN is on. Nothing is broken; the traffic is simply going the wrong way.

What Allow LAN does

Allow LAN tells ROOT to leave your local network out of the tunnel. Traffic to private and link-local addresses goes straight across your LAN as it normally would, while everything bound for the internet still travels through the encrypted VPN.

It is a precise carve-out, not an all-or-nothing switch. ROOT excludes exactly the private, link-local and multicast ranges that local devices use, and keeps DNS working through the tunnel, so you keep full VPN protection for your browsing and only your own network becomes reachable again.

When to turn it on, and when not to

Switch Allow LAN on when you need to print at home, reach a NAS, cast to a TV, control smart-home gear, or connect to a console or PC on the same network while the VPN is running. For most people at home, leaving it on is convenient and safe.

Leave it off when you are on a network you do not trust, like public café or hotel Wi-Fi. On those networks you generally do not want to be reachable by, or reach out to, other machines nearby, so the stricter full-tunnel behaviour with the kill-switch is the safer default.

How to turn on Allow LAN in ROOT VPN

  1. Open ROOT VPN and go to Settings.
  2. Find Allow LAN access under the connection options and switch it on.
  3. Reconnect, or connect if you are not already, so the setting applies to the tunnel.
  4. Your local devices, printer, NAS, Chromecast, consoles, are reachable again, while the rest of your traffic stays encrypted.

Local network access: common questions

Does Allow LAN weaken my VPN protection?
Only for your own local network. Traffic to private and link-local addresses stays on your LAN, but everything bound for the internet still goes through the encrypted tunnel. Your browsing keeps full VPN protection.
Which devices does it let me reach?
Anything on your local network: printers, NAS drives, Chromecasts and other cast targets, smart-home hubs, game consoles and other computers on the same Wi-Fi or LAN.
Should I leave it on all the time?
At home, it is convenient and safe to leave on. On untrusted networks like public Wi-Fi, turn it off so you stay isolated from other machines nearby and keep the stricter full-tunnel behaviour.
Does it work with the kill-switch?
Yes. Allow LAN carves out only your local network. The kill-switch still blocks internet traffic if the tunnel drops, so your public connection stays protected.

More from the ROOT VPN blog

Read more about what ROOT can do, or browse every post.

Keep your VPN on without losing your devices.

Create a free account, flip on Allow LAN, and use the VPN and your local network together.

Get ROOT VPN, free