Full tunnel and split tunnel

A full-tunnel configuration routes the intended default traffic through the VPN. A split-tunnel configuration includes only selected destinations, applications or address ranges.

The exact behavior depends on operating-system routing, client features and server policy. The label alone does not show which traffic is protected.

Why organizations use split tunneling

Split tunneling can keep local services available, reduce VPN server bandwidth and route only private resources through a corporate network. It may also improve performance for traffic that does not need the tunnel.

  • Access private resources through the VPN
  • Keep local printers or devices reachable
  • Reduce unnecessary traffic through the server
  • Apply different policies to different destinations

Security tradeoffs

Traffic outside the tunnel receives no protection from the VPN. Incorrect routes or DNS settings may send sensitive traffic through an unintended path.

Document the required destinations, test both included and excluded traffic, and review rules whenever networks or applications change.

Continue learning

Browse the VPN learning center, review secure configuration delivery, or check client compatibility.