The split may be defined by destination prefixes, applications, domains, or policy. It changes which path traffic takes; it does not itself decide whether the traffic or endpoint is trustworthy.
Organizations use split tunneling to reduce gateway load, avoid indirect routes to nearby cloud services, or preserve local access. Its security depends on complete route definitions and consistent handling of DNS, IPv4, IPv6, updates, and failures.
Key points
Policy scopeIdentify every corporate destination and supporting dependency that must use the tunnel. Treat local-subnet access, personal applications, and direct cloud paths as explicit decisions rather than defaults.
Endpoint and network controlsApply host firewall, patching, endpoint detection, identity controls, and secure DNS to both paths. A hostile local network remains a threat.
Operational checksTest route changes, reconnects, captive portals, IPv6, name resolution, software updates, and tunnel outages. Logs should show which policy selected each path without collecting unnecessary personal browsing data.
Important limitationOnly traffic selected for the tunnel receives its protection and centralized inspection. Direct traffic may bypass organizational filtering and telemetry, while a compromised endpoint can communicate across both paths. Full tunneling removes that particular bypass but introduces gateway capacity and availability dependencies; it is not a complete security control either.