VPN split tunneling is a feature that allows users to selectively route some of their network traffic through an encrypted VPN tunnel, while other data is sent directly through the public internet. NordLayer provides two types of VPN split tunneling: Include mode and Exclude mode.
- Include mode can be enabled on a Gateway.
- Exclude mode can be enabled on a Gateway or a Browser Extension.
Each mode supports up to 100 entries.
What is include split tunneling?
Include split tunneling lets you choose specific IP addresses or subnets whose traffic will be encrypted and routed through NordLayer's secure servers. All other traffic will access the internet directly, without encryption. This setup lets users select exactly which traffic should be protected, enhancing security where it's needed while optimizing your network's bandwidth and performance.
You can set up Include split tunneling by enabling the feature in the Gateway settings.
Supported address types (Gateway): IP addresses and subnets.
How does include split tunneling work?
With Include split tunneling, IT administrators designate certain IP addresses or subnets to be routed through the VPN tunnel. Only the selected traffic is encrypted and securely directed through NordLayer's servers — everything else connects to the internet directly.
What is exclude split tunneling?
Exclude split tunneling takes the opposite approach: all traffic is encrypted and routed through the VPN tunnel except for the addresses specified by administrators. Listed addresses will have direct internet access without encryption, ensuring faster access and reduced load on the corporate VPN network. This is particularly useful for accessing sites that don't allow VPN connections or for reducing latency on web-based applications like video conferencing tools.
Exclude split tunneling can be enabled on a Gateway or a Browser Extension.
Supported address types:
- Gateway — IP addresses, subnets, and domains/subdomains.
- Browser Extension — domains/subdomains and wildcards.
Presets
To simplify exclude split tunneling, NordLayer offers ready-made presets for popular services like Google Meet, Zoom, and Microsoft Teams. Instead of manually inputting every network address for a service, you can simply select a preset, and NordLayer handles the underlying destinations automatically.
This is particularly beneficial for VoIP and video conferencing. Bypassing the VPN tunnel for services like Zoom or Teams typically requires managing an extensive list of IP addresses and FQDNs. Because providers constantly update their infrastructure, maintaining these lists manually is tedious and error-prone.
NordLayer solves this by automatically updating presets in the background. When a provider changes its IPs or domains, the preset updates itself, ensuring your traffic continues to bypass the tunnel without interruption or manual intervention.
Presets can also be combined with manual entries. You can select presets for major services while still adding custom IP addresses, subnets, domains, or wildcards to accommodate your organization's unique network requirements.
How does exclude split tunneling work?
When using Exclude split tunneling, all traffic is encrypted and routed through the VPN tunnel by default. Only the addresses listed by administrators will bypass the tunnel and connect directly to the internet. This lets organizations maintain broad VPN protection while carving out exceptions for specific resources that benefit from a direct connection.
How do I choose between Include and exclude split tunneling?
The choice depends on your specific needs:
- Include mode is ideal when you want to secure traffic to a defined set of IP addresses or subnets while leaving everything else on the open internet. It is available on Gateways only.
- Exclude mode is ideal when you want all traffic protected by default but need certain destinations — such as video conferencing tools or sites that block VPNs — to bypass the tunnel. It is available on Gateways (supporting IPs, subnets, and domains) and on the Browser Extension (supporting domains/subdomains and wildcards).
Note: In case you have any questions or are experiencing any issues, please feel free to contact our 24/7 customer support team.