How does a split tunnel VPN Work?

How does a split tunnel VPN Work?

Split tunneling is a VPN feature that divides your internet traffic and sends some of it through an encrypted virtual private network (VPN) tunnel, but routes the rest through a separate tunnel on the open network. Typically, split tunneling will let you choose which apps to secure and which can connect normally.

What is the benefit of split tunneling?

One advantage of using split tunneling is that it alleviates bottlenecks and conserves bandwidth as Internet traffic does not have to pass through the VPN server. Another advantage is in the case where a user works at a supplier or partner site and needs access to network resources on both networks throughout the day.

How does split tunneling work with OpenVPN?

When you set up split tunneling, only traffic that is destined for the subnets on your Internal LAN will go through the VPN tunnel. Other traffic will go through your employee’s normal Internet connection. Here’s a basic diagram of how traffic flows when split tunneling is enabled on OpenVPN Access Server:

Can a VPN connect to an OpenVPN access server?

When a VPN client connects to OpenVPN Access Server, it creates a tunnel. Data transferred is encrypted, through the Internet to the VPN server and connected to your Internal LAN. OpenVPN Access Server can be configured to route all traffic destined to the internet and not just the internal LAN through that tunnel as well.

When to use split tunnel on or off?

The split tunnel ON is the default value for the internet access setting associated with User Groups, Networks, and Hosts. Only when a network is set as VPN Egress does the split tunnel OFF value appears as an option for the internet access setting associated with User Groups, Networks, and Hosts.

How does a tunnel work with a VPN?

When a VPN connection is set up, an encrypted tunnel is created over the Internet to the Cloud VPN Region. The VPN connection appears as a virtual network interface to the computer in addition to the existing LAN interface.