Split tunneling

A remote access VPN setting that sends only traffic for the organisation's networks through the tunnel, while other traffic goes straight to the internet from the device.

Split tunneling is a remote access VPN configuration in which only traffic bound for the organisation’s networks enters the encrypted tunnel. Everything else, such as general web browsing, leaves the device directly over the local internet connection. The alternative, often called full tunnel, sends all of the device’s traffic through the organisation first. NIST SP 800-46 Rev. 2, the telework and remote access guide, discusses the choice.

The case for split tunneling is performance and cost: internet and cloud traffic avoids a detour through head office, and the VPN gateway carries less load. The case against is visibility and exposure. Traffic that bypasses the tunnel also bypasses the organisation’s inspection, such as a secure web gateway and outbound monitoring, and the device is connected to the untrusted internet and the internal network at the same time, so a compromised laptop can become a bridge between them. Designs built on zero trust reduce that concern by checking each request rather than trusting whatever arrives through the tunnel.

Exam relevance: a scenario may describe a remote user whose infected laptop reached internal systems while browsing freely, or ask which setting would make all remote traffic pass central inspection. Candidates are expected to link split tunneling with reduced visibility and bridging risk, and full tunnel with central inspection at a cost in speed.