For what is split tunneling on a VPN laptop cmmc, the plain-English answer is that a remote laptop must not use a VPN to reach company systems while using a separate direct internet connection at the same time. CMMC 2.0 Level 2 practice SC.L2-3.13.7 requires the organization to prevent that arrangement by disabling split tunneling so external web traffic, cloud traffic, and other internet-bound traffic also travel through the organization’s VPN security controls.
What is split tunneling on a VPN laptop cmmc, and what does SC.L2-3.13.7 require?
NIST SP 800-171 Rev. 2 requirement 3.13.7 states:
“Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).”
For an ISSO or FSO, the wording becomes more manageable when each clause is separated:
- “Prevent remote devices” means the contractor must use technical controls, not merely a policy statement asking users not to browse the internet while connected to the VPN. The organization must configure managed remote-access devices and VPN services to stop the condition.
- “Simultaneously establishing … connections with organizational systems” means a laptop is connected to company resources such as a file server, enclave application, virtual desktop, engineering repository, identity service, or other system in scope.
- “Communicating via some other connection to resources in external networks” means the same laptop has another active path to the public internet or an outside service that bypasses the VPN. Examples include a home-router connection, coffee-shop Wi-Fi, cellular hotspot, personal proxy, or another network adapter.
- “I.e., split tunneling” identifies the prohibited configuration: internal traffic goes through the VPN, while internet-bound traffic goes directly to the local network.
A split-tunnel VPN configuration may send traffic for 10.20.0.0/16 through the VPN while sending Microsoft 365, public websites, software-update traffic, and other destinations directly to the user’s home router. A full-tunnel configuration instead makes the VPN the default route while connected. The VPN gateway then applies the contractor’s DNS filtering, firewall rules, logging, web controls, and monitoring before allowing traffic onward.
The security concern is not that every external website is automatically malicious. The concern is that a compromised or hostile external connection can provide a path toward a laptop that is also connected to organizational resources. A full-tunnel VPN reduces that exposure by ensuring the organization can inspect and control the remote device’s network communications while it has access to the environment.
Who does the split-tunneling requirement apply to, and when is it triggered?
SC.L2-3.13.7 applies to remote devices that connect to organizational systems, especially managed laptops used outside the contractor’s controlled facilities. For a small contractor, this commonly includes Windows laptops issued to employees, engineers’ travel laptops, administrator workstations used from home, and managed devices assigned to consultants when they access systems handling CUI or supporting the CMMC assessment scope.
The control is triggered when a remote device connects to organizational resources through remote access. The user may be working from home, a hotel, a customer site, an airport, or a cellular hotspot. The physical location is less important than the connection pattern: if the laptop has a remote-access connection to company systems, it must not simultaneously send external traffic over a separate bypass route.
This is not normally a requirement to force all internet traffic through a VPN when a laptop is inside the office and connected only to the organization’s internal network. It is also not a ban on internet use. Rather, it requires that internet use from a remotely connected device be routed through the organization’s approved remote-access path while the device can reach internal systems.
Scope decisions still matter. An ISSO should identify every remote-access method that can reach the CMMC assessment scope: traditional VPNs, always-on VPN clients, zero-trust access clients, virtual desktop gateways, and administrative remote-access tools. If an alternative access method gives a remote endpoint meaningful connectivity to in-scope systems, the organization should document how it prevents an equivalent split-path condition.
What does compliant full-tunnel remote access look like in practice?
An assessor will generally look for a consistent technical design, evidence that it is operating, and proof that exceptions do not quietly reintroduce split tunneling. The following are concrete examples of conditions that support SC.L2-3.13.7 compliance.
| Situation | Compliant condition | Useful assessment evidence |
|---|---|---|
| Managed Windows laptop using GlobalProtect | The Palo Alto Networks GlobalProtect gateway is configured for full tunnel, with no split-tunnel include or exclude list. The client receives a default route through the VPN. | Gateway configuration export, VPN profile screenshot, route-table output, and a successful test showing public IP traffic exits through the company security stack. |
| Microsoft Always On VPN deployment | The Windows VPN profile uses force tunneling, and device management prevents users from creating or modifying a competing VPN profile. | Intune configuration profile, assigned-device report, VPN profile settings, and a sampled laptop showing 0.0.0.0/0 routed through the VPN interface. |
| Remote engineering workstation | The laptop connects through a full-tunnel VPN before accessing source code, engineering data, or a virtual desktop. DNS requests also use the VPN-provided resolver rather than the home router’s resolver. | VPN configuration, DNS settings, firewall or secure web gateway logs, and a documented remote-access test procedure. |
| Contractor laptop with Wi-Fi and cellular capability | The approved VPN remains full tunnel regardless of whether the laptop uses home Wi-Fi, hotel Wi-Fi, or a cellular hotspot. A user cannot retain direct internet egress while the VPN is connected. | Test records across Wi-Fi and hotspot connections, endpoint configuration baselines, and evidence that local administrator rights are restricted. |
Consider a 42-person engineering company, Northbridge Applied Research, that performs SBIR prototype work and maintains a small CUI enclave. Its engineers use company-issued Windows 11 laptops to access a Git repository, a controlled SharePoint library, and a virtual desktop hosting test data. Northbridge configures GlobalProtect as a full-tunnel service: once connected, the default route, DNS requests, and browser traffic go to its firewall. The firewall applies URL filtering and logs outbound sessions. An engineer at home can still use the internet, but the home router is no longer the laptop’s direct exit path while the engineering VPN is active.
That organization should retain more than a screenshot of a VPN setting. A defensible evidence set includes the approved remote-access standard, the current VPN configuration export, endpoint-management settings that prevent unapproved network changes, a list of authorized exceptions, and test results from a representative laptop. The assessor should be able to trace the policy requirement to the technical enforcement and then to operating evidence.
A second example is a 17-person STTR contractor whose staff use Microsoft 365 for ordinary business but access a separate virtual desktop environment for proposal, research, and CUI-related work. The contractor may allow ordinary Microsoft 365 access outside the VPN when the virtual desktop is not in use. However, when the laptop initiates the remote-access session into the controlled environment, its VPN profile must force internet traffic through the approved gateway. If the organization deliberately excludes Microsoft 365 traffic from the VPN during that session, it should expect difficulty demonstrating that it has prevented split tunneling under SC.L2-3.13.7.
There can be narrow operational complications, such as local printing, captive portals, voice quality, or SaaS performance. Those are not automatic justifications for split tunneling. If a technical exception is necessary, the ISSO should determine whether the remote device can still communicate directly with external networks while connected to organizational systems. If it can, the exception conflicts with the control’s objective and should be redesigned, such as by using a virtual desktop, a separate non-CUI workflow, or a secured gateway-based solution.
What should an assessor expect to see for SC.L2-3.13.7?
An assessor is likely to ask whether remote endpoints can reach organizational systems while directly browsing the internet through a local network. A credible answer is supported by configuration and testing, not by intent alone. Prepare evidence showing that full tunneling is enabled, that the setting applies to all relevant remote-access groups, and that users cannot easily override it.
- A current network or remote-access diagram showing remote laptops, the VPN or access gateway, DNS, firewall, and internet egress path.
- VPN configuration evidence showing full-tunnel or force-tunnel behavior and the absence of broad split-tunnel exclusions.
- Endpoint-management evidence showing deployment to the relevant laptop population.
- Sample route and DNS tests from a remote laptop on a non-corporate network.
- Change records and periodic review evidence for any VPN routing changes.
Frequently asked questions about split tunneling
Is split tunneling allowed under CMMC Level 2?
For remote devices connected to organizational systems in scope, SC.L2-3.13.7 requires the organization to prevent split tunneling. A configuration that allows direct external internet access while the device is connected to internal systems does not meet the stated control objective.
Does SC.L2-3.13.7 require all VPN traffic to go through the company network?
In practice, yes, for the remote-access scenario covered by the control. The implementation guidance recommends disabling split tunneling so traffic for external networks and the internet goes through the VPN rather than through a separate local connection.
How do I test whether a VPN laptop is split tunneling?
Connect the laptop to the VPN from a home or hotspot network, then inspect its route table, DNS resolver, and public egress IP address. A full-tunnel connection normally routes the default route through the VPN and shows the organization’s approved egress address; a split-tunnel connection often leaves the local gateway as the default internet route.
Does using Microsoft 365 outside the VPN count as split tunneling?
If Microsoft 365 traffic bypasses the VPN while the same laptop has remote connectivity to organizational systems, it can constitute split tunneling. The relevant question is whether the device is simultaneously using a separate external-network path while connected to the organization’s systems.
Next step: Review every active remote-access profile and have your IT administrator document a full-tunnel test from one representative CUI-scope laptop before your next CMMC evidence review.