VPN split tunneling

Protect company traffic without routing everything through the office

VPN split tunneling is the decision about which traffic goes through the company network and which goes straight out. Send everything through the office and you ruin video calls and turn the gateway into a bottleneck. Send nothing and you lose the control you installed a VPN to get.

The situation

Everyone is remote, or remote enough that it stops being an exception. Their laptops carry the company’s work and their own lives at the same time, on the same connection.

The full-tunnel decision was made years ago because it was simpler to reason about. Then the video calls started stuttering, the gateway started being the thing everybody complains about, and somebody started asking why a private video is crossing the company firewall at all.

Why the usual answers do not fit

Full tunnel is defensible on paper and miserable in practice. Every megabyte of somebody’s afternoon travels to the office and back, and the line you sized for email is now carrying video.

No tunnel removes the bottleneck and the control with it. You no longer know what reached what.

A manual exception list is the compromise, and it is a list somebody has to maintain forever, on every device, with no way to check it is still what the document says.

The shape of it

Company traffic is protected. Personal traffic is not yours to carry.

Company traffic goes through your network. Everything else leaves the device directly, and that is a choice you make per group.

Your networkcompany trafficeverything elsethe decision point is on the device Laptop Gateway ServersPublic internetDecision point
secure tunnelunprotected pathcontrol channelalready yours
How QS-WAN solves it

Split tunneling vpn rules are written once, centrally, and enforced on the device by the agent. The traffic that belongs to the company goes through the tunnel and gets the firewall rules, the DNS filtering and the audit trail. Everything else goes out the way it always did.

The rule lives with the policy, not on the laptop.

Change it once and it changes everywhere, without touching a device or asking anyone to reconnect.

It is the same policy engine as everything else.

The rules about who reaches what and the rules about which traffic is carried are not two systems with two consoles.

And there is the part people rarely say out loud.

Employees do not want their personal traffic crossing their employer’s network, and being able to say plainly that it does not is worth more than most security features.

Who this is for

This is usually the situation when

The question nobody asks until week three

What happens when the rule is wrong.

A split that is too generous quietly carries traffic you did not mean to carry, and you find out in an audit. A split that is too tight breaks an application, and you find out in a support ticket from somebody who cannot do their job.

Because the rule is central, both are fixed in one place and take effect without anybody reinstalling anything. That is the difference between a policy you can tune and a decision you made once and have to live with.

What your people see

Nothing. That is the point. They open the app, and the split happens underneath.

Integration

What it takes, and what it leaves alone

What you need

Nothing new. It is a setting.

What changes

Tunnel mode, in the console, per VLAN.

What doesn't

The device. No change is made there.

Key features of this use case

The features this use case relies on

Firewall rules

DNS filtering

Security policy management

See it running on your own network

It is free, there is nothing to sign, and nobody is going to sell you anything.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top