NordLayer VPN Split Tunneling: Feature Review

Feature Spotlight: NordLayer’s VPN Split Tunneling

For modern IT teams, finding the sweet spot between ironclad security and seamless network performance is a daily struggle. Routing 100% of your data through a VPN guarantees comprehensive protection, but it often bottlenecks essential applications. Conversely, bypassing the VPN entirely sacrifices administrative control and security.

NordLayer’s split tunneling offers the perfect compromise. This dynamic traffic management tool empowers organizations to dictate exactly how data flows—allowing you to encrypt all data by default with specific exemptions, or selectively secure only designated traffic. Instead of a rigid “all-or-nothing” approach, administrators can craft centralized policies tailored to their workforce’s unique operational needs.


The Mechanics of VPN Split Tunneling

A conventional corporate VPN funnels every byte of internet traffic through a secure, encrypted server. While this ensures total coverage, it unnecessarily increases latency for applications that don’t require external encryption—such as standard SaaS platforms or unified communications tools like Microsoft Teams.

Split tunneling fundamentally alters this architecture. It allows administrators to divide network data into two independent streams:

  • A secure, encrypted path routed directly through the VPN.
  • A direct, unencrypted path straight to the open internet.

Crucially, these pathways are dictated by centralized IT rules, completely removing the burden of choice from the end user.


Deploying Split Tunneling in NordLayer

Implementing split tunneling within NordLayer requires no external software; it integrates natively into your existing Control Panel alongside your standard network rules.

Configuration Steps

  • Gateway-Level (Include/Exclude): Navigate to the “Network” tab in the Control Panel, select “Gateways,” and pick your preferred mode. You can designate specific IP addresses or subnets for inclusion, or highlight IPs, subnets, and domains for exclusion. Once saved, this policy acts instantly across the organization.
  • Browser Extension (Exclude Mode): For browser-specific exclusions, navigate to “Settings,” click “Browser Extension Settings,” and input the domains, subdomains, or wildcard URLs you wish to bypass the VPN.

To streamline administration, NordLayer features automated presets for heavily utilized platforms like Zoom, Google Meet, and Microsoft Teams. Rather than manually updating a provider’s shifting FQDNs and IP addresses, IT simply enables the preset. NordLayer automatically manages the backend updates as the provider alters its infrastructure. These presets can also be layered seamlessly with your own custom manual entries.

Availability Note: Gateway-based Include and Exclude modes are standard on both Core and Premium tiers. Browser extension Exclude mode is a Premium-exclusive feature. Premium users can further enhance their setup by pairing gateway split tunneling with advanced features like Firewall as a Service (FWaaS) and site-to-site connectivity.


Include vs. Exclude: Understanding the Two Modes

Split tunneling operates in two distinct, highly complementary modes to address different architectural needs.

FeatureInclude Mode (Opt-In)Exclude Mode (Opt-Out)
Core LogicOnly explicitly listed traffic uses the VPN. All other traffic goes to the open internet.All traffic uses the VPN by default, except for explicitly listed exceptions.
Ideal Use CaseWhen the VPN is only needed for a handful of internal resources (e.g., admin panels, private cloud environments).Broad, zero-trust protection where only a few highly trusted or latency-sensitive apps bypass the tunnel.
Configuration ScopeGateway only (IP addresses and subnets).Gateway (IPs, subnets, domains) & Browser Extension (domains, wildcards).
Primary BenefitMinimizes gateway load and keeps the VPN scope extremely focused.Maximizes default security while allowing safe, direct paths for trusted apps.

The Strategic Advantages of Split Tunneling

At its core, split tunneling is designed to maximize both security and productivity. The cascading benefits affect everyone in the organization:

  • Optimized Performance: By keeping non-essential traffic off the VPN, latency-sensitive applications (like video conferencing) run smoother and faster.
  • Reduced Infrastructure Strain: Limiting tunnel traffic directly decreases the bandwidth load on your VPN gateways, ensuring highly responsive connections for critical tasks.
  • Frictionless Access to Blocked Sites: Certain government portals and financial institutions actively block VPN traffic. Exclude mode allows users to access these necessary sites directly without dropping their overall VPN protection.
  • Maintenance-Free Presets: Automated updates for major SaaS platforms mean IT administrators no longer need to hunt down and manually update changing IP lists.

Impact by Stakeholder

  • For IT Administrators: Gain centralized, granular control over data routing without touching individual devices. It drastically reduces support tickets regarding slow apps or blocked sites, freeing up time for strategic initiatives.
  • For End Users: Experience a frictionless workflow. Collaboration apps run at peak speed, and strict banking sites load normally. There is no need to manually toggle the VPN on and off; the intelligence operates invisibly in the background.
  • For the Organization: Lower operational costs and maximize cloud tool performance. It enables a pragmatic Zero Trust architecture—protecting highly sensitive internal data while giving trusted, low-risk traffic a high-speed direct lane.

Is NordLayer Split Tunneling Right for You?

If your current blanket-VPN strategy is generating complaints about sluggish video calls, preventing access to essential banking websites, or overloading your gateways, split tunneling is the definitive solution.

It shines brightest in hybrid or remote setups where employees constantly bounce between private internal resources and public SaaS applications. Include mode is your go-to if you only have a few private apps to protect. Exclude mode is ideal for maintaining comprehensive security while letting known-safe traffic bypass the bottleneck. Furthermore, the browser extension makes domain-level exclusions incredibly simple for teams living in web apps.

While split tunneling does not negate your overarching compliance requirements, its centralized management ensures that administrators maintain strict oversight regarding exactly what data is permitted to bypass the encrypted tunnel.


Take Command of Your Network Routing

Stop letting rigid VPN defaults dictate your network’s efficiency. With NordLayer’s split tunneling, you design traffic flows that match your organization’s actual operational habits.

Empower your IT team to secure what truly matters while letting the rest run fast and unimpeded, all manageable from a single, intuitive dashboard.

About the Author

Agnė Srėbaliūtė | Senior Cybersecurity Copywriter

Bringing over ten years of expertise spanning PR, media, and advertising, Agnė specializes in translating complex cybersecurity and technology concepts into accessible insights. Her focus areas include zero trust architecture, internet infrastructure, networking, and IP address management.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.