What is a VPN tunnel, and does all of your traffic have to go through it?

Summary

A VPN tunnel is an encrypted wrapper around your traffic that carries it across the internet to a VPN server, where it's unwrapped and sent on. Whether all of a device's traffic goes into that tunnel, or only traffic bound for company systems, is a routing setting. A full tunnel sends everything through the company's VPN, which lets IT log and filter it. A split tunnel sends only the internal traffic, which cuts load and, on a cloud service like AWS Client VPN, data transfer charges.

Wrapping one packet inside another

Traffic on the internet moves in packets, each labeled with where it's going. A VPN encrypts each packet and puts it inside a new packet addressed to the VPN server. WireGuard's own description is that it "securely encapsulates IP packets over UDP." The server strips off the outer layer and forwards the original packet to its real destination.

Anyone watching the network in between sees encrypted traffic headed for the VPN server. They can't see what's inside or the real destination. That sealed path is what people mean by the tunnel.

The differences between WireGuard, OpenVPN and IPsec, and what names like AES-256 refer to, are in our article on protocols and ciphers.

Routes decide what enters the tunnel

Having a tunnel doesn't mean every packet uses it. The device's routing table decides which destinations go in.

WireGuard makes this very visible. Each peer has an AllowedIPs line listing the address ranges that belong to it. Put 0.0.0.0/0 there, which is a wildcard for every IPv4 address, and WireGuard will encrypt packets "with any destination IP address" and send them to that peer. Put a single office range such as 192.168.88.0/24 there instead, and only traffic for the office goes through the tunnel. The WireGuard site describes the list as working like a routing table on the way out and an access control list on the way in.

Full tunnel or split tunnel

Sending everything through the VPN is called a full tunnel. Sending only some destinations is a split tunnel.

AWS Client VPN is a good illustration because it documents both. By default it overwrites the client's route table with a 0.0.0.0/0 entry so that all traffic goes over the VPN. Turn on split-tunnel and only traffic for the networks in the endpoint's route table uses the tunnel. AWS gives two reasons you might want that: only the AWS-bound traffic crosses the tunnel, and less traffic leaves AWS, "therefore reducing the data transfer cost." One operational catch it mentions is that any change to the route table while split-tunnel is on resets every client connection.

With a full tunnel, video calls and web browsing also pass through the company's gateway. All of it has to fit through that gateway, and all of it is visible there. With a split tunnel, anything not headed for company systems goes straight out through the user's home or hotel connection, and the company never sees it.

Check which one a product does out of the box

Defaults differ between products. Tailscale, by default, only carries traffic between devices on your Tailscale network and leaves ordinary internet traffic alone. To send everything through the company, you set one machine up as an exit node, and each device has to opt in to using it. While a device uses an exit node it loses access to its own local network by default, so a home printer, for example, stops being reachable.

NIST's telework guidance tells organizations to plan remote access security on the assumption that the networks between the employee's device and the organization "cannot be trusted." Which tunnel mode follows from that depends on the company's policy. If IT has to see and filter web browsing on work laptops, that points to a full tunnel. If the job is only to protect access to internal systems, a split tunnel does it with less traffic through the gateway.

Sources

Related on this site


Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.