VPN Split Tunneling - Benefits and Security Trade-offs
About 2 min read
VPN split tunneling is a configuration in which, rather than routing all traffic through the VPN when connected, only specific traffic is sent through the VPN tunnel while the rest connects directly to the internet. With the spread of remote work, many companies have adopted it to optimize bandwidth and improve the user experience. As of 2025, with the spread of SASE (Secure Access Service Edge), new architectures that integrate split tunneling with cloud security are becoming mainstream.
When the Routing List Falls Behind Reality
In a configuration that divides traffic between two paths, the routing specification itself becomes something that has to be maintained. First, which traffic goes outside is specified through a list of names or destinations, but what those entries point to changes independently of the side that uses them. When the provider adds or replaces its endpoints, there is no guarantee that the change reaches whoever wrote the settings, so the list keeps the shape it had when it was written while falling behind reality. Once it falls behind, traffic meant to go outside travels inside the path, and traffic meant to stay inside goes out. Drift in either direction still functions as behaviour, so it comes to attention not as a malfunction but as something found during a later reconciliation. Second, the unit of routing and the unit the user has in mind do not coincide. Where one screen produces traffic to several destinations, only part of it ends up on the other path even though the split was drawn by feature. This mismatch usually stays out of sight and surfaces only when a condition that holds on just one of the paths is involved, which makes the cause hard to guess at. Third, once the path is divided, the record of the traffic is divided across two places as well. Tracing the order of events around an operation afterwards requires reconciling both records, yet there is no guarantee that the time reference or the level of detail is the same in each. What should be decided together with the split is whether which path was taken will remain recoverable afterwards.
Split Tunneling Conceptual Diagram
Comparison with Full Tunneling
Full tunneling (routing all traffic through the VPN) offers high security because all traffic can be inspected by the company's security appliances, but the load concentrates on the VPN server, which can degrade the quality of video meetings such as Zoom and Teams. With split tunneling, only access to internal systems goes through the VPN while SaaS and general internet browsing connect directly, so in some cases bandwidth can be reduced by 50 to 70%.
Security Risks and Countermeasures
The biggest risk of split tunneling is that traffic not routed through the VPN falls outside the company's security monitoring. A device infected with malware could communicate with a C2 server via a path outside the VPN. Effective countermeasures include strengthening endpoint security, protecting DNS queries with DNS over HTTPS, and gaining visibility into SaaS usage with a CASB (Cloud Access Security Broker). Protect your VPN connection account with a strong, random password and secure the remote work environment.
Was this article helpful?