ABOUTVPNS / FIELD NOTE 04
Full Tunnel vs. Split Tunnel
Learn which traffic uses a VPN, how DNS fits, and what to test when the route changes.
Full tunnel: a default path through the VPN
A full-tunnel design generally directs internet traffic through the VPN gateway. This can centralize network policy and inspection, while also putting more traffic through the gateway and its internet connection. It may change latency and the public address services observe. Local-network exceptions and platform behavior still need checking; the label full tunnel is not a substitute for reading the deployed policy.
Split tunnel: selected traffic uses the VPN
A split-tunnel design routes designated networks or applications through the tunnel and allows other traffic to use another path. For example, a business may send internal application traffic to its gateway while a video meeting reaches the internet directly. This can reduce gateway load, but the resulting boundaries must be deliberate. Do not change an organization's routing policy yourself to improve one application.
Names and routes must agree
An internal name may only resolve through an organization resolver. Sending the packet down the correct route will not help if the name resolves incorrectly or not at all. Conversely, successfully resolving a name does not prove that its traffic uses the intended tunnel. Browser encrypted DNS, operating-system settings and the VPN client can interact, so document both name resolution and routing.
Test a small set of real workflows
Create a checklist with one public website, one approved internal application, any required printing or local device, and a video call if that is part of the job. Check each while connected, after sleep and reconnect, and after a network change. Record whether failures concern a name, connection, authorization or performance rather than grouping every symptom as the VPN being broken.
Plan failure behavior
Decide what should happen when the tunnel is unavailable. Should internet traffic stop, continue directly, or continue only for certain applications? Test both IPv4 and IPv6 when they are present. A design can intentionally allow local traffic without being defective; a leak is traffic escaping a boundary that the policy intended to enforce.
Sources and Further Reading
Sources support the technical concepts. Examples and checklists are our educational synthesis, not a provider review or a substitute for current deployment guidance.