Remote Access VPN Design: Split Tunnelling, Always-On, and What Replaced Them
A remote access VPN places a user's device onto the corporate network from wherever they are. The design decisions — what traffic goes through it, whether it is always connected, and what the device reaches once it is on — determine both the security posture and whether people work around it. Full tunnel and split tunnel Full tunnel sends all of the device's traffic through the VPN, including internet-bound traffic, which then exits through the corporate perimeter. The benefit is that every inspection and filtering control applies to a remote user exactly as it does in the office, and the organization has visibility of what the device does. The cost is that every video call and cloud application takes a detour through headquarters, adding latency and consuming concentrator and internet capacity that scales with the remote population. Split tunnel sends only corporate-destined traffic through the VPN and lets everything else go direct. The benefit is performance and f...