Missing split tunnel route

T Ken 60 Reputation points
2026-10-08T02:10:03.7633333+00:00

Remote users connected through the VPN are unable to access resources hosted on internal subnets. What is the recommended way to add our organization's IP address ranges to the split-tunneling inclusion list so that traffic destined for internal resources is routed through the VPN correctly ?

Windows for business | Windows 365 Business
0 comments No comments

2 answers

Sort by: Most helpful
  1. Harry Phan 33,805 Reputation points Independent Advisor
    2026-10-08T07:20:46.9366667+00:00

    Hi T Ken,

    For a Windows VPN profile, add the organization’s internal subnet prefixes to the VPN RouteList so traffic to those networks is routed through the VPN tunnel. For example, use Add-VpnConnectionRoute -ConnectionName "VPN-Name" -DestinationPrefix "10.20.0.0/16" for each required subnet. Verify the routes with Get-NetRoute or route print after connecting. Also ensure the VPN gateway has a valid return route to the VPN client address pool; otherwise, the connection may still fail even with the correct client-side routes.

    Harry P.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-08T02:10:15.39+00:00

    For Windows VPN scenarios, the recommended approach is to configure split tunneling routes for the VPN connection and add the organization’s internal destination prefixes there so traffic for those subnets uses the VPN, while other traffic can use the local network.

    If the VPN is managed through Intune on Windows devices:

    1. Open the Windows VPN profile settings in Intune.
    2. Go to Split Tunneling.
    3. Set Split tunneling to Enable.
    4. In Split tunneling routes for this VPN connection, add each internal subnet as a route by entering:
      • the destination prefix
      • the prefix size

    This is the supported way to include internal IP ranges in the VPN path.

    If the issue is specific to Microsoft 365 optimization, only Microsoft 365 Optimize endpoints should be excluded from the VPN path, while internal corporate subnets should remain in the VPN inclusion list. For Windows built-in VPN, this model is described as Force Tunneling with Exclusions, where defined destinations can use the physical interface and all other traffic continues through the VPN.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.