Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security When should organisations prioritise forced tunneling over split…
Cyber Security

When should organisations prioritise forced tunneling over split tunneling for remote users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

Forced tunneling is the safer choice when security and traffic control matter more than local network convenience. Use it when you need all non LAN traffic routed through the exit node, especially on devices that handle sensitive work or operate under stricter compliance rules. Split tunneling fits cases where local LAN access is necessary and the risk profile is lower.

Why the traffic path matters more than the tunnel label

Forced tunneling is the right default when the organisation wants a single control point for remote-user traffic. It lets security teams inspect, log, filter, and apply policy to traffic before it reaches the internet, SaaS, or other external services. Split tunneling reduces latency and preserves local access, but it also creates two simultaneous trust paths that must be governed differently.

The practical decision is less about the VPN feature itself and more about whether the remote endpoint should be treated like an extension of the corporate network or a partially trusted device with independent internet access. That distinction becomes important when monitoring, content filtering, DLP, or egress control are part of the security model.

For broader remote-access policy design, NIST’s Cybersecurity Framework 2.0 and the control emphasis in CIS Controls v8 both support the idea that traffic control, logging, and access governance should follow the risk of the environment, not user convenience alone.

When forced tunneling is the better choice

Prioritise forced tunneling when the remote session can reach sensitive systems, regulated data, or security-sensitive applications. It is also the safer choice when your organisation needs consistent inspection of outbound traffic, centralized DNS or web filtering, or evidence that remote endpoints are not bypassing corporate controls by using local internet paths.

It is especially appropriate where compliance obligations, incident response visibility, or data loss prevention matter more than endpoint convenience. In those cases, letting some traffic exit locally can weaken the organisation’s ability to prove that user activity, downloads, and exfiltration paths are subject to the same controls as office-based access.

When organisations rely on managed remote devices, tunnel all non-local traffic through the security stack so that access, logging, and response decisions are applied uniformly. The operational logic is similar to zero trust thinking: do not assume the user location makes the traffic safe.

NHIMG’s Regulatory and Audit Perspectives section is useful here because the same governance pressure that drives tighter identity and access control also drives stronger routing control for sensitive remote work.

When split tunneling is acceptable, and what to verify first

Split tunneling is reasonable when users need reliable access to local printers, conferencing tools, home-network resources, or low-risk public services, and when the organisation has accepted that not all remote traffic needs corporate inspection. It can also reduce load on the VPN infrastructure and improve user experience for bandwidth-heavy applications.

The trade-off is that the organisation gives up some visibility and control over the non-tunneled path. That is usually acceptable only if the endpoint has strong device posture, the workload is low sensitivity, and the security team has explicit compensating controls such as endpoint protection, conditional access, and tightly scoped application access.

Before allowing split tunneling, verify that the device is managed, patched, and protected against local-network abuse. The main failure mode is not simply “internet traffic goes elsewhere”, but that a compromised endpoint can bridge corporate and local paths in ways that bypass inspection or make lateral movement easier.

For identity and access programmes that depend on strong operational discipline, NHIMG’s Lifecycle Processes for Managing NHIs is a good companion reference because it reinforces the same principle: access paths should be governed according to sensitivity and lifecycle risk, not treated as equally safe by default.

Risk and Threat Considerations

Split tunneling increases exposure when local and corporate traffic are allowed to coexist on the same endpoint. The risk is not theoretical: an attacker who compromises the device may gain a less-monitored route to corporate resources, while the local internet path can provide a way to bypass logging, filtering, or inspection controls.

Failure mechanism: The endpoint becomes a dual-homed trust bridge, so malicious code, stolen session state, or unauthorized traffic can move between local and corporate contexts without all flows passing through the same control plane.

Impact: Reduced visibility, weaker egress control, and a larger opportunity for data exfiltration or lateral movement, especially where remote users handle regulated data or connect to high-value internal services.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, while NIS2 and DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Identity Management, Authentication, and Access ControlRemote tunneling choice affects who can reach corporate resources and under what trust conditions.
PR.PT — Protective TechnologyForced tunneling is a protective technology decision that centralizes inspection and traffic control.
Recommendation — Apply access controls that match the sensitivity of remote traffic paths. Route sensitive remote traffic through centralized protective controls.
CIS Controls v86 — Access Control ManagementTunneling policy is an access-path control that changes how remote users reach internal and external services.
8 — Audit Log ManagementForced tunneling supports consistent logging and traffic visibility for remote sessions.
Recommendation — Restrict remote access paths according to device and data risk. Capture remote-user network activity where inspection and traceability matter.
NIST Zero Trust (SP 800-207)3 — Policy Engine and Enforcement PointForced tunneling aligns with centralized enforcement of remote traffic policy.
Recommendation — Enforce remote traffic policy through a central decision and enforcement path.
NIS2Article 21 — Cybersecurity Risk-Management MeasuresRemote-access routing should support risk management measures, monitoring, and access control obligations.
Recommendation — Align remote access routing with documented risk-management and monitoring measures.
DORAArticle 9 — ICT Risk Management FrameworkFinancial entities need controlled remote access paths that support ICT risk management and resilience.
Recommendation — Use the stricter tunneling model where remote access supports resilience and control.

Practitioner Guidance

Decision rule: If the remote device can access sensitive applications, administrative interfaces, regulated data, or anything that would materially change incident response if exfiltrated, default to forced tunneling. If users genuinely need local-network access, treat split tunneling as an exception that needs a documented risk acceptance and compensating controls.

What to verify: Check whether your VPN, DNS, web filtering, and logging controls still see the traffic that matters most. If the answer is no, split tunneling is usually creating a governance gap rather than a user-experience improvement.

Practitioner takeaway: Choose forced tunneling whenever security teams need the remote user’s traffic to be observable, enforceable, and defensible; choose split tunneling only when local access is operationally necessary and the residual risk is consciously accepted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org