Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk6 min

VPN Split Tunneling Explained: Benefits, Risks, and When to Use It

VPN split tunneling can ease VPN congestion by sending selected traffic direct, but that traffic bypasses protections tied to the VPN path. Learn the trade-offs and Windows approach.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VPN split tunneling sends selected traffic through a VPN while routing other traffic outside it. It can ease VPN congestion and shorten paths to cloud services, but traffic outside the tunnel no longer receives protections that depend on that VPN connection. Whether it is a good choice depends on which routes are excluded, what other safeguards apply, and how much control an organization needs.

What is VPN split tunneling?

Split tunneling is a routing policy that divides network traffic between a VPN tunnel and another route, often the device’s ordinary internet connection. NIST’s glossary defines it as routing organization-specific traffic through an SSL VPN while sending other traffic through the remote user’s default gateway (NIST CSRC Glossary).

As an Amazon Associate I earn from qualifying purchases.

The exact meaning can vary by VPN product and configuration. In enterprise remote access, the usual distinction is whether traffic destined for corporate resources uses the VPN and whether other destinations do not. Microsoft’s built-in Windows VPN documentation makes a further distinction: its “force tunneling with exclusions” method sends selected destinations over the physical interface while routing the rest through the VPN. That is not necessarily the same configuration another vendor calls split tunneling (Microsoft Learn: VPN routing).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This article focuses mainly on enterprise remote-access VPNs. Consumer privacy VPN apps may use “split tunneling” to describe app- or destination-based choices for a different purpose; the security and monitoring implications depend on that product’s design.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Why do organizations use split tunneling?

Reduce VPN congestion and unnecessary detours

With a forced tunnel, a remote worker’s internet-bound traffic may travel back to the organization’s network before going out to its destination. This “hairpin” route can consume VPN capacity and add latency. Routing selected cloud-service traffic directly can reduce that load and may improve responsiveness, depending on the network architecture and conditions.

Keep exceptions targeted

Microsoft recommends a narrow split-tunnel approach for certain high-volume, latency-sensitive Microsoft 365 traffic. Its guidance names Teams, SharePoint, and Exchange Online, and recommends prioritizing dedicated IP ranges in the service’s “Optimize” category. Other internet traffic can remain on the VPN (Microsoft Learn: Overview of VPN split tunneling for Microsoft 365).

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

Microsoft says its Optimize endpoints account for “around 70–80% of Microsoft 365 service traffic volume” in its endpoint classification and service context; that estimate is not a general statistic about VPN traffic. Microsoft also says traffic routed directly to Microsoft 365 remains encrypted and integrity-validated by the service and client stacks. Those statements apply to Microsoft’s services and guidance, not automatically to other apps or destinations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What are the security risks?

Traffic outside the tunnel bypasses VPN-path controls

Split tunneling does not inherently disable encryption. Rather, traffic sent outside the VPN does not receive protection from that VPN tunnel and may bypass enterprise gateway inspection or policies attached only to that path. Whether it has other encryption or security controls depends on the application, endpoint, and organization’s design.

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

Less visibility and a possible network bridge

NIST warns that split tunneling can prevent an organization from examining much of a remote worker’s traffic and protecting its confidentiality and integrity. It also describes the risk that a device connected simultaneously to trusted and untrusted networks could inadvertently bridge them. NIST advises organizations to consider disabling split tunneling on untrusted networks, particularly wireless hotspots (NIST SP 800-46 Rev. 2).

NIST’s IPsec VPN guidance strongly discourages split tunneling because of its security complications, while recognizing that organizations may use it to reduce remote-access bandwidth demands and avoid carrying traffic unrelated to the organization (NIST SP 800-77 Rev. 1). The appropriate choice therefore depends on the organization’s threat model and controls, not simply on whether split tunneling is enabled.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.

Which routing model fits?

Microsoft describes a range of approaches, from narrow exceptions to broader direct access. The trade-offs are not just about speed: they also affect inspection, endpoint risk, and how much policy maintenance is required (Microsoft Learn: Microsoft 365 networking overview).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Model Which destinations use the VPN? Operational trade-off
Narrow split tunnel Corporate traffic and most internet traffic stay on the VPN; selected destinations, such as designated Microsoft 365 endpoints, go direct. Limits exceptions, but endpoint routes must be kept current and aligned with the organization’s controls.
Broader direct routing More trusted services or destinations use a direct route; remaining traffic may still use the VPN. Can reduce VPN load further, but requires broader assessment and policy decisions.
Selective tunneling Only traffic to corporate addresses uses the VPN; other traffic goes direct. Moves more traffic outside the VPN and assumes stronger maturity in access controls; Microsoft frames it as a model for organizations well along a Zero Trust path.
Forced tunneling All traffic is routed through the VPN unless explicitly excluded. Centralizes traffic through organizational gateways, but can add capacity demands and detours for cloud services.
No VPN for internal access Internal services are published through modern access controls rather than reached through a conventional VPN tunnel. Requires a different access architecture and implementation effort; it is not merely a routing toggle.

Use these models as policy choices rather than a universal progression. A narrower exception may be easier to govern than broad direct routing, while a fully forced tunnel may be necessary where centralized inspection is a priority.

Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should an organization decide?

Before changing routes, weigh the scope of excluded traffic against the controls available outside the VPN. A decision should account for:

  • Destination scope: Which exact services, address ranges, or applications will bypass the tunnel?
  • Inspection and monitoring: Will traffic outside the VPN still be inspected, logged, and protected by another approved control?
  • Capacity and user experience: Is VPN congestion or a long route causing a measurable problem, and is direct routing likely to improve it?
  • Device and network trust: Are endpoints managed, and what happens when a device is also connected to a local or untrusted network?
  • Policy maintenance: Who will keep destination routes aligned with changing service endpoints and the organization’s VPN platform?
  • Geography: Will direct egress perform acceptably for users in each location? Microsoft notes a China-specific caveat for users connecting to the worldwide Microsoft 365 instance because direct-egress performance can vary.

Microsoft’s recommendation is specific to its services and network guidance; it is not a blanket instruction to send all Microsoft 365 or all internet traffic outside the VPN. Confirm the applicable endpoint categories and ranges for the organization’s deployment before configuring exceptions.

How do you configure exclusions in Windows VPN?

Microsoft documents a force-tunnel-with-exclusions method for Windows 10 and Windows 11. In that approach, the VPN profile forces traffic through the tunnel, then adds IP address-and-prefix exclusion routes for selected destinations. Excluded traffic uses the physical interface; the rest continues through the VPN and existing security gateways (Microsoft Learn: VPN routing).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Review the VPN and endpoint requirements. Confirm that the organization’s VPN platform supports the profile and route behavior, and identify the current published IP ranges for the destinations to exclude.
  2. Set the VPN profile to force tunneling. Use the organization’s supported Windows VPN configuration and deployment method.
  3. Add only the approved exclusion routes. Define the destination IP address and prefix routes that should use the physical interface. Avoid treating a static list as permanent.
  4. Deploy and validate the profile. Microsoft says profiles can be deployed through management methods such as Intune. Check that excluded destinations use the intended route and that all other traffic remains on the VPN.
  5. Maintain and review the routes. Reconcile exclusions with updated service endpoint information and the organization’s security policy.

For Microsoft 365, Microsoft advises using its published endpoint ranges rather than assuming FQDN- or AppID-based rules cover every scenario. Service endpoint categories and ranges can change, so route configuration needs an owner and a review process (Microsoft 365 IP Address and URL web service).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.