When a device is on your VPN, it shouldn't also have an open door straight to the public internet.
What it actually means
Split tunneling lets a remote device route some traffic through your VPN and other traffic straight to the internet — which can bridge an outside network into yours. Configure VPN clients to force all traffic through the tunnel (full tunnel) so the remote device can't simultaneously talk to external resources outside your control.
Pass or fail — an assessor needs a "yes" to each
- Are VPN clients configured to disable split tunneling (full-tunnel)?
- Is that setting enforced by policy or configuration rather than left to the user?
What to have ready
- VPN client configuration / profile showing split tunneling disabled
- Policy statement requiring full-tunnel VPN
Where teams trip up
- Default VPN profiles that allow split tunneling
- Letting users toggle the setting
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in System & Communications Protection (3.13)
3.13.1 — Protect your boundaries3.13.2 — Build security in by design3.13.3 — Separate user and admin functions3.13.4 — Stop data leaking through shared resources3.13.5 — Wall off your public-facing systems3.13.6 — Deny all, permit by exception3.13.8 — Encrypt CUI in transit3.13.9 — Drop idle network sessions3.13.10 — Manage your encryption keys3.13.11 — FIPS-validated cryptography3.13.12 — Control cameras and microphones3.13.13 — Control mobile code3.13.14 — Control and monitor VoIP3.13.15 — Protect session authenticity3.13.16 — Encrypt CUI at rest