GUIDE
Banks and local apps without turning access off: how profile routing works
Published: 2026-09-20 · Updated: 2026-09-20
The official sing-box remote profile sets routing: local and Russian services may go direct, other traffic stays in the tunnel. That is the FAQ wording, not a promise that every bank will always open. Exact rules depend on the current profile, so refresh Connect. We do not publish domain lists. If an app still breaks, refresh the profile, check the official client and the OS permission.
Why people turn access off for a bank — and why that may be unnecessary
A common gesture: turn the tunnel off, open a bank or a local app, turn it back on. People do that when all traffic takes one path and the app “dislikes” a foreign route.
Vinipuch describes another mechanism: rules travel inside the remote profile. Some local and Russian traffic may go direct without a manual toggle. That is profile convenience, not a guide to evade network limits.
What the FAQ says about banks and local services
The public source is the FAQ. The answer: yes, banks and local services can work without turning access off. The remote profile sets routing: local and Russian services may go direct, other traffic through the tunnel. Exact rules depend on the current profile.
The remote profile sets routing
You do not build a route table by hand. The link from the bot or cabinet brings current rules with the servers. We do not promise a separate “split” toggle in the client UI: the rules live inside the profile.
“May” is not “always guaranteed”
The FAQ does not publish a list of banks, apps or domains. We do not claim every bank and every government site always opens without turning access off. You check your own service. Public docs do not describe routing differences across Economy, Standard, Comfort and Premium — we will not invent them.
What it looks like for you
Typical picture: local or Russian traffic goes direct, the rest through the VLESS · Reality tunnel on official sing-box. The protocol is the same on every plan.
Local and RU traffic direct; the rest through the tunnel
That is how the FAQ describes the profile’s intent. It is not a Windows split-tunneling toggle and not a downloadable allow-list. This page has no DIY JSON.
Rules depend on the current profile
A server change can change routes. Open Connect again so the client pulls current contents. A file you saved is not the source of rules.
If a bank or local app still breaks
User-side steps only. No recipes for evading the network.
Refresh the remote profile
Connect again, import as Remote. Often enough after a server change.
Official client
SFI, SFA, SFW, SFM or SFL from the download page. A shell from chat may ignore profile rules.
OS permission
Without the network-configuration permission, apps behave unpredictably.
When to write to support
Device, client, time, expected versus actual. No tokens, login cookies or wallet secrets. The full “tunnel will not start” checklist is the sibling guide.
What this page does not promise
No bank or domain list. No guarantee a given app will always open. No claim that “government sites” are a separate category beyond the FAQ wording. No instructions to edit routes by hand.
If you need your own server and a full rules admin, that is a different product. Vinipuch is a managed remote profile.
Where next
Start and import live in Getting started. The client lives in the official sing-box explainer and on the download page. Plans are on /en/pricing/. Data handling is in the logging policy, briefly.
Short answers
Do all banks always work without turning access off?
No. The FAQ says they may. Rules depend on the current profile. You check your own service.
Where is the list of banks and domains?
There is no public list. We do not publish an allow-list.
Can I edit routes in JSON?
That path is not documented publicly and is not taught here. Current rules arrive in the remote profile.
Should I turn access off if the app already opened?
If it works with the profile on, leave it. If not, refresh the profile and follow the user-side checklist.