| Description | This article describes how to enable split-tunneling in Windows 10 (L2TP/PPTP VPN). |
| Scope | FortiGate. |
| Solution |
In this example, L2TP was used.
All traffic from this machine is going through the FortiGate.
To enable split-tunneling:
Result: A split-tunnel route has automatically been created to its respective classful address.
For Windows 11:
Note 1:
config vpn ipsec phase2-interface
Note 2: PPP (Point to Point Protocol) is the foundation for L2TP, which uses IPCP (IP Control Protocol) to negotiate the IP address. Since IPCP historically did not transmit a subnet mask, Windows implemented Classful Networking logic as a fallback mechanism:
If this behavior causes conflicts (for example, if the local network is also using the 10. x.x.x range), check the 'Disable class-based default route' box in the Advanced TCP/IP settings (IPv4) of the VPN connection:
Related articles: Technical Tip: Split tunneling on L2TP/IPsec VPN between FortiGate and Windows 10. Technical Tip: Resolving internet connectivity issues with L2TP. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.