Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

VPN split tunneling sends some traffic through a VPN while other traffic takes a different route, often through the device’s regular internet connection. It can reduce VPN congestion and improve access to cloud services, but traffic outside the tunnel may also bypass the organization’s inspection and protection controls. Whether it makes sense depends on which routes are excluded, how devices are managed, and what security controls cover the direct connection.

What is VPN split tunneling?

Split tunneling is a traffic-routing policy, not a single universal VPN setting. NIST’s glossary defines it as routing organization-specific traffic through an SSL VPN while sending other traffic through the remote user’s default gateway. In practice, an organization might send requests for internal systems through the VPN and let selected cloud-service traffic connect directly.

Consumer privacy VPNs may use split tunneling for a different purpose, such as choosing which apps use the VPN. The guidance and examples here focus on enterprise remote access, where the key question is which destinations use the corporate tunnel and its associated controls. See the NIST CSRC glossary definition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why do organizations use it?

Reduce unnecessary VPN routing

With forced tunneling, remote users’ cloud-service traffic may travel to the corporate network and then back out to the internet. That extra routing can consume VPN capacity and add latency. Sending carefully selected destinations directly to their services can reduce that load and may improve responsiveness, depending on the network path and configuration.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Keep exceptions narrow

Microsoft recommends a targeted split-tunnel approach for key Microsoft 365 scenarios, including Teams, SharePoint, and Exchange Online. Its guidance prioritizes dedicated IP ranges in the service’s Optimize category; other internet traffic can remain on the VPN. Microsoft describes the directly routed traffic in this scenario as still protected by encryption and integrity validation from the Microsoft 365 service and client stacks. That assurance applies to the Microsoft service and setup described in its guidance, not automatically to other destinations or applications. See Microsoft’s VPN split-tunneling guidance for Microsoft 365.

Microsoft estimates that its Optimize endpoints account for around 70–80% of Microsoft 365 service traffic volume, according to its undated guidance accessed in 2026. This is an estimate for Microsoft’s endpoint classification and service context, not a general measure of VPN traffic or a guaranteed reduction in VPN load.

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

Is split tunneling safe?

It is not inherently unsafe, and it does not mean that every connection loses encryption. The important distinction is that traffic routed outside the VPN does not get protection from that VPN tunnel or automatically pass through security controls attached only to the tunnel. Its protection depends on the destination service, endpoint security, and the organization’s other controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST warns that split tunneling can prevent an organization from examining much of a teleworker’s network traffic and protecting its confidentiality and integrity. It also describes a bridging risk: a device connected to both a trusted organizational network and an untrusted network could create an unintended path between them. For untrusted networks, particularly wireless hotspots, NIST says organizations should consider disabling split tunneling. Its SP 800-46 Rev. 2 guidance discusses both the efficiency benefits and these security risks; its IPsec VPN guidance strongly discourages split tunneling because of its security complications.

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

Which routing approach fits?

Microsoft’s scenario guidance describes choices ranging from a few direct-routed endpoints to access models that send most traffic outside the VPN. The appropriate choice depends on the destinations, inspection requirements, device trust, VPN capacity, and the organization’s ability to manage routes and access controls.

Approach What uses the VPN Trade-offs
Narrow split tunnel Corporate destinations use the VPN; selected high-volume, latency-sensitive service endpoints connect directly. Limits the exception and can relieve VPN load. Requires current, accurate destination routes and clear controls for direct traffic.
Broader direct routing A wider set of trusted services connects outside the VPN. May reduce VPN load further, but requires more assessment of which destinations are trusted and how direct traffic is protected.
Selective tunneling Only corporate-address traffic uses the VPN; other traffic goes direct. Can reduce reliance on the VPN for general connectivity, but Microsoft describes this as a model for organizations well along a Zero Trust path.
Full or forced tunneling All traffic, or all traffic except defined exclusions, uses the VPN. Centralizes routing through corporate controls, but can add VPN capacity demand and indirect paths to cloud services.
No VPN for published internal services Users access internal services through modern access controls rather than a VPN tunnel. Changes the access model rather than simply changing routes; Microsoft notes that broader models can require more assessment and implementation effort.

These are policy choices, not security rankings. A narrow exception may be easier to govern than broad direct routing, but only if the route list and safeguards are maintained. Microsoft’s scenario discussion is available in its Microsoft 365 continuity guidance.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you split tunnel a VPN on Windows?

Microsoft’s built-in Windows VPN documentation covers Windows 10 and Windows 11 and describes a method it calls force tunneling with exclusions. This is not identical to every vendor’s definition of split tunneling: the profile forces traffic through the VPN, then sends defined destinations over the physical interface. Other traffic continues through the VPN and existing security gateways.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Set the VPN profile to force tunneling. Configure the profile using the organization’s chosen management method; Microsoft lists management options such as Intune.
  2. Add IP address and prefix exclusion routes. Define the selected destination ranges that should use the physical interface rather than the VPN.
  3. Use current destination data. For Microsoft 365, align exclusions with Microsoft’s maintained endpoint information rather than assuming FQDN or AppID rules cover every scenario.
  4. Validate the resulting paths and controls. Confirm that excluded destinations use the intended direct route and that other traffic still reaches the VPN and its security gateways.

Routes need to match both the current endpoint list and the organization’s VPN platform and policy. Microsoft’s service endpoint categories and ranges can change, so a hard-coded list should not be treated as timeless. Its Windows instructions are at VPN routing for Windows.

Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.

What should an organization evaluate first?

  • Scope: Identify exactly which destinations bypass the VPN. Start with the smallest set that addresses the capacity or latency problem.
  • Inspection: Determine which monitoring, filtering, and policy controls apply to direct traffic, rather than assuming VPN controls cover it.
  • Device and network trust: Consider device management, endpoint safeguards, simultaneous network connections, and whether users may connect through untrusted Wi-Fi.
  • Operational upkeep: Establish who updates routes when service endpoints change and how changes are tested and deployed.
  • User location and service path: Performance depends on geography and network architecture. Microsoft notes a China-specific caveat for users connecting to the worldwide Microsoft 365 instance, where direct egress performance can vary.

Microsoft’s recommendation is vendor guidance for its services, not a universal performance guarantee. An organization should weigh expected VPN relief against the visibility and security controls it gives up on excluded routes, then test the policy in its own environment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.