split-tunnel VPN
also: split tunneling
A VPN configuration where only specific traffic is routed through the VPN tunnel while other traffic uses the local network connection directly.
Split-tunneling allows a VPN client to selectively route traffic: some applications or destinations go through the encrypted VPN tunnel, while others bypass it and connect directly to your local network or the internet. This differs from full-tunnel VPN, where all traffic is encrypted and routed through the VPN gateway.
For example, you might configure split-tunneling to route corporate traffic through your company VPN while allowing local streaming services or printer access to use your direct internet connection. This can improve performance for non-sensitive traffic and reduce VPN server load.
However, split-tunneling can create security risks: traffic outside the tunnel is unencrypted and exposed, potentially allowing attackers to intercept sensitive data or perform DNS-based attacks. Many organizations disable split-tunneling to enforce complete encryption of all user traffic.