HomeControl Library › 3.13.7
3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.7 — Block split tunneling on VPNs

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

When a device is on your VPN, it shouldn't also have an open door straight to the public internet.

What it actually means

Split tunneling lets a remote device route some traffic through your VPN and other traffic straight to the internet — which can bridge an outside network into yours. Configure VPN clients to force all traffic through the tunnel (full tunnel) so the remote device can't simultaneously talk to external resources outside your control.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library