What Is FQDN Split Tunneling?

Network Security

What Is FQDN Split Tunneling?

FQDN split tunneling is a method of configuring which domains will route through a VPN’s encrypted tunnel that uses fully qualified domain names instead of IP addresses. FQDN split tunneling is a powerful strategy that can reduce administrative burden, speed up VPN connections, and improve continuity.

Understanding Split Tunneling

Most commonly, split tunneling is handled by an IP address. IT administrators will exclude certain IP addresses from accessing the VPN tunnel, forcing them to move through a different (split) channel.

While this is a precise form of protecting a connection, it is also extremely labor-intensive to manage.

Although there are tactics to speed up listing blocked IP addresses, administrators will normally have to group addresses in ranges. For instance:

The simple fact that IP addresses can range across hundreds of specifics makes this a time-consuming pursuit. Plus, network administrators have to regularly update this list to:

Instead of using this laborious method of split tunneling, businesses are using FQDN split tunneling .

As FQDNs contain an entire domain address, administrators can use them to rapidly block entire sources of connection from entering the VPN. If you want to exclude an entire FQDN from a specific company, you only need to use the wildcard ‘*’.

For instance, you could block connections to Microsoft with *.microsoft.com, which would ensure all connections from this domain bypass your VPN.

Role of SSL VPNs in Remote Access

A secure sockets layer (SSL) VPN is another form of VPN that allows businesses to create secure VPN tunnels for any type of device. They’re most frequently used to access internal resources within a company’s network or to directly connect to enterprise apps.

SSL VPNs use the transport layer security (TLS) protocol to encrypt connections, providing them with a highly secure and rapid method of creating an encrypted tunnel and facilitating connection. The exact version of the protocol will be whichever is currently on the device an employee is using.

This is another reason to keep all devices updated to their latest software releases.

The Pros of FQDN Split Tunneling

There are a number of benefits of FQDN split tunneling that businesses and network administrators can take advantage of:

The Cons of FQDN Split Tunneling

There are also some cons of FQDN split tunneling that network administrators should be aware of:

Some FQDN split tunneling systems will help prevent the first two of these cons from occurring by offering alternative monitoring and security systems for the denied stream of traffic.

Configuring FQDN Split Tunneling

In Harmony SASE, IT administrators can configure FQDN split tunneling from the Networks section.

Steps to Configure FQDN Split Tunneling

  1. Navigate to Networks and select the specific network to modify.
  2. Access Split Tunneling Settings by clicking the “…” icon and selecting Split Tunneling.
  3. Enter the FQDNs and specify whether they should be included or excluded from the VPN tunnel.

Manual vs. Automatic Configuration

By default, split tunneling is inactive (Automatic mode), meaning all traffic routes through the VPN. To enable FQDN split tunneling, switch to Manual mode and define which FQDNs should be routed through or bypass the VPN. This approach optimizes resource allocation, network efficiency, and security.

By implementing FQDN split tunneling, administrators gain better control over network traffic, ensuring improved performance and secure access management.

FAQ

What’s the difference between FQDN split tunneling and application-based tunneling? FQDN split tunneling filters traffic based on domain names (e.g., *.zoom.us), while application-based tunneling uses application fingerprinting or metadata to determine what traffic should bypass the VPN. The former is more transparent and scalable across platforms, but app-based tunneling may be more precise in complex environments.

Can FQDN split tunneling be used for regulatory compliance? Yes, selectively routing sensitive data through the VPN while excluding low-risk domains can help align with data residency and industry compliance frameworks. However, to meet audit requirements, organizations must log traffic and document exclusion rules thoroughly.

Does FQDN split tunneling work with dynamic or CDN-based domains? FQDN split tunneling can handle wildcard domains (e.g., *.microsoft.com), but it may struggle with content delivery networks (CDNs) or services that use constantly changing subdomains. DNS caching and resolution controls are critical to ensure consistent behavior.

How can DNS over HTTPS (DoH) affect FQDN split tunneling? DoH can encrypt DNS requests, hiding them from network-level tools that enforce FQDN policies. If devices use external DNS resolvers over HTTPS, the split tunneling engine might fail to detect which domains are being accessed. Admins should enforce corporate DNS usage to avoid this blind spot.

What are signs your FQDN split tunneling is misconfigured? Common red flags include increased helpdesk tickets for connection failures, VPN bandwidth congestion despite exclusions, or unusual data access patterns. Continuous monitoring and feedback from end-users are essential to fine-tune and validate your tunnel policies.