VPN split tunneling sends selected traffic through a VPN while routing other traffic outside it. It can ease VPN congestion and shorten paths to cloud services, but traffic outside the tunnel no longer receives protections that depend on that VPN connection. Whether it is a good choice depends on which routes are excluded, what other safeguards apply, and how much control an organization needs.
What is VPN split tunneling?
Split tunneling is a routing policy that divides network traffic between a VPN tunnel and another route, often the device’s ordinary internet connection. NIST’s glossary defines it as routing organization-specific traffic through an SSL VPN while sending other traffic through the remote user’s default gateway (NIST CSRC Glossary).
As an Amazon Associate I earn from qualifying purchases.
The exact meaning can vary by VPN product and configuration. In enterprise remote access, the usual distinction is whether traffic destined for corporate resources uses the VPN and whether other destinations do not. Microsoft’s built-in Windows VPN documentation makes a further distinction: its “force tunneling with exclusions” method sends selected destinations over the physical interface while routing the rest through the VPN. That is not necessarily the same configuration another vendor calls split tunneling (Microsoft Learn: VPN routing).
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteThis article focuses mainly on enterprise remote-access VPNs. Consumer privacy VPN apps may use “split tunneling” to describe app- or destination-based choices for a different purpose; the security and monitoring implications depend on that product’s design.
#1 Best Overall
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Why do organizations use split tunneling?
Reduce VPN congestion and unnecessary detours
With a forced tunnel, a remote worker’s internet-bound traffic may travel back to the organization’s network before going out to its destination. This “hairpin” route can consume VPN capacity and add latency. Routing selected cloud-service traffic directly can reduce that load and may improve responsiveness, depending on the network architecture and conditions.
Keep exceptions targeted
Microsoft recommends a narrow split-tunnel approach for certain high-volume, latency-sensitive Microsoft 365 traffic. Its guidance names Teams, SharePoint, and Exchange Online, and recommends prioritizing dedicated IP ranges in the service’s “Optimize” category. Other internet traffic can remain on the VPN (Microsoft Learn: Overview of VPN split tunneling for Microsoft 365).
Rank #2
- 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
- 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
- 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
- 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.
Microsoft says its Optimize endpoints account for “around 70–80% of Microsoft 365 service traffic volume” in its endpoint classification and service context; that estimate is not a general statistic about VPN traffic. Microsoft also says traffic routed directly to Microsoft 365 remains encrypted and integrity-validated by the service and client stacks. Those statements apply to Microsoft’s services and guidance, not automatically to other apps or destinations.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →What are the security risks?
Traffic outside the tunnel bypasses VPN-path controls
Split tunneling does not inherently disable encryption. Rather, traffic sent outside the VPN does not receive protection from that VPN tunnel and may bypass enterprise gateway inspection or policies attached only to that path. Whether it has other encryption or security controls depends on the application, endpoint, and organization’s design.
Rank #3
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
Less visibility and a possible network bridge
NIST warns that split tunneling can prevent an organization from examining much of a remote worker’s traffic and protecting its confidentiality and integrity. It also describes the risk that a device connected simultaneously to trusted and untrusted networks could inadvertently bridge them. NIST advises organizations to consider disabling split tunneling on untrusted networks, particularly wireless hotspots (NIST SP 800-46 Rev. 2).
NIST’s IPsec VPN guidance strongly discourages split tunneling because of its security complications, while recognizing that organizations may use it to reduce remote-access bandwidth demands and avoid carrying traffic unrelated to the organization (NIST SP 800-77 Rev. 1). The appropriate choice therefore depends on the organization’s threat model and controls, not simply on whether split tunneling is enabled.
Rank #4
- 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
- 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
- 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
- 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Which routing model fits?
Microsoft describes a range of approaches, from narrow exceptions to broader direct access. The trade-offs are not just about speed: they also affect inspection, endpoint risk, and how much policy maintenance is required (Microsoft Learn: Microsoft 365 networking overview).
| Model | Which destinations use the VPN? | Operational trade-off |
|---|---|---|
| Narrow split tunnel | Corporate traffic and most internet traffic stay on the VPN; selected destinations, such as designated Microsoft 365 endpoints, go direct. | Limits exceptions, but endpoint routes must be kept current and aligned with the organization’s controls. |
| Broader direct routing | More trusted services or destinations use a direct route; remaining traffic may still use the VPN. | Can reduce VPN load further, but requires broader assessment and policy decisions. |
| Selective tunneling | Only traffic to corporate addresses uses the VPN; other traffic goes direct. | Moves more traffic outside the VPN and assumes stronger maturity in access controls; Microsoft frames it as a model for organizations well along a Zero Trust path. |
| Forced tunneling | All traffic is routed through the VPN unless explicitly excluded. | Centralizes traffic through organizational gateways, but can add capacity demands and detours for cloud services. |
| No VPN for internal access | Internal services are published through modern access controls rather than reached through a conventional VPN tunnel. | Requires a different access architecture and implementation effort; it is not merely a routing toggle. |
Use these models as policy choices rather than a universal progression. A narrower exception may be easier to govern than broad direct routing, while a fully forced tunnel may be necessary where centralized inspection is a priority.
Best Value
- Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
- A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
- Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
- Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
- Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
How should an organization decide?
Before changing routes, weigh the scope of excluded traffic against the controls available outside the VPN. A decision should account for:
- Destination scope: Which exact services, address ranges, or applications will bypass the tunnel?
- Inspection and monitoring: Will traffic outside the VPN still be inspected, logged, and protected by another approved control?
- Capacity and user experience: Is VPN congestion or a long route causing a measurable problem, and is direct routing likely to improve it?
- Device and network trust: Are endpoints managed, and what happens when a device is also connected to a local or untrusted network?
- Policy maintenance: Who will keep destination routes aligned with changing service endpoints and the organization’s VPN platform?
- Geography: Will direct egress perform acceptably for users in each location? Microsoft notes a China-specific caveat for users connecting to the worldwide Microsoft 365 instance because direct-egress performance can vary.
Microsoft’s recommendation is specific to its services and network guidance; it is not a blanket instruction to send all Microsoft 365 or all internet traffic outside the VPN. Confirm the applicable endpoint categories and ranges for the organization’s deployment before configuring exceptions.
How do you configure exclusions in Windows VPN?
Microsoft documents a force-tunnel-with-exclusions method for Windows 10 and Windows 11. In that approach, the VPN profile forces traffic through the tunnel, then adds IP address-and-prefix exclusion routes for selected destinations. Excluded traffic uses the physical interface; the rest continues through the VPN and existing security gateways (Microsoft Learn: VPN routing).
- Review the VPN and endpoint requirements. Confirm that the organization’s VPN platform supports the profile and route behavior, and identify the current published IP ranges for the destinations to exclude.
- Set the VPN profile to force tunneling. Use the organization’s supported Windows VPN configuration and deployment method.
- Add only the approved exclusion routes. Define the destination IP address and prefix routes that should use the physical interface. Avoid treating a static list as permanent.
- Deploy and validate the profile. Microsoft says profiles can be deployed through management methods such as Intune. Check that excluded destinations use the intended route and that all other traffic remains on the VPN.
- Maintain and review the routes. Reconcile exclusions with updated service endpoint information and the organization’s security policy.
For Microsoft 365, Microsoft advises using its published endpoint ranges rather than assuming FQDN- or AppID-based rules cover every scenario. Service endpoint categories and ranges can change, so route configuration needs an owner and a review process (Microsoft 365 IP Address and URL web service).
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




