CompTIA Network+ (N10-009)Network OperationsHard
A company allows remote employees to connect via VPN to access internal file shares and applications. To reduce load on the VPN concentrator and conserve bandwidth, management wants employees' general internet browsing traffic to go directly to the internet rather than passing through the corporate tunnel. Which VPN configuration should be implemented?
- AFull tunnel
- BSite-to-site tunnel
- CSplit tunnel
- DClientless VPN
Show answer & explanationAnswer & explanation
Correct answer: C. Split tunnel
A split tunnel configuration routes only traffic destined for the corporate network through the VPN tunnel while allowing all other internet-bound traffic to travel directly through the user's local internet connection, reducing concentrator load and bandwidth usage.
Why the other options are wrong
- A. A full tunnel routes all traffic, including general internet browsing, through the VPN, increasing concentrator load.
- B. A site-to-site tunnel connects two networks/gateways, not an individual remote user's laptop.
- D. A clientless VPN provides browser-based access to specific applications without a full network tunnel client.
Split Tunnel VPN
A VPN configuration in which only traffic destined for the corporate network is sent through the encrypted tunnel, while other traffic uses the local internet connection directly.
- Reduces bandwidth and load on the VPN concentrator
- Full tunnel sends all traffic through the VPN, offering more security oversight
- Split tunneling can pose security risks since local traffic bypasses corporate inspection
Memory trick: Split tunnel = 'fork in the road' for corporate vs internet traffic.