How to configure split tunneling in wireguard sys-vpn NetVM?

In my ivpn guide, I remember I wrote something to allow bypassing the vpn for a few addresses, this does not work from the vpn qube itself though, but only in qubes connected to it.

In IVPN App 4.2 setup guide see Access local LAN / addresses

With this setup, you do not need to modify the vpn configuration, the bypass is handled by nftables.