Split tunneling enables routing of only specific traffic over the VPN connection, while other traffic accesses the Internet directly.
You can globally define (for all SDP users) which IP addresses are routed through or excluded from the VPN connections. Alternately, you can enable SDP users to configure their own split tunneling definitions.
In line with security best practices, split tunneling configuration is enforced from the Cato Management Application by default, and all traffic is routed to the VPN tunnel (split tunneling is disabled).
The Split Tunnel section lets you configure the split tunneling settings for all the Cato Clients in the account.

You can configure all the VPN clients in the organization to use the split tunnel policy that is defined in the Cato Management Application. You can configure the following rules for traffic to the defined IP range:
-
Exclude: traffic to the IP range is routed directly to the Internet. All other traffic is routed through the VPN connection.
-
Include: traffic to the IP range is routed through the VPN connection. All other traffic is routed directly to the Internet.
To configure the split tunnel settings for all VPN clients:
-
From the navigation menu, click Access > Client Access.
-
Expand the Split Tunnel section.
-
From the Enforcement drop-down menu, select Cato Management Application.
-
Select the Enable Split Tunnel.
-
Select the Action for the split tunnel rules, Include or Exclude.
-
Configure rules for traffic that can bypass the VPN connection:
-
Click New.
The Add panel opens.
-
Enter the Name for the rule.
-
In Subnet, enter the IP range that is included or excluded for the VPN tunnel.
-
Click Apply.
-
-
To delete a rule, click
(Delete).
-
Click Save.
You can configure to let each SDP user configure the split tunnel settings for themselves. For more information, see Split Tunnel Configuration for Specific SDP Users.
Note
Note: For more about configure split tunneling for a Client, see the Cato Client Installation and User Guide for the relevant operating system.
0 comments
Please sign in to leave a comment.