FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
lestopace
Staff
Staff
Article Id 208910
Description This article describes how to enable split-tunneling in Windows 10 (L2TP/PPTP VPN).
Scope FortiGate.
Solution

In this example, L2TP was used.

 

lestopace_7-1649469982057.png

 

All traffic from this machine is going through the FortiGate.

 

lestopace_9-1649470157892.png

 

To enable split-tunneling:

 

  1. Go to L2TP properties in Control Panel\Network and Internet\Network Connections.

 

lestopace_2-1649469341765.png

 

  1. Then on the VPN Connection Properties window, go to the Networking tab, select Internet Protocol Version 4 (TCP/IPv4), and select Properties.

 

lestopace_3-1649469467746.png

 

  1. On the Internet Protocol Version 4(TCP/IPv4) Properties, select Advanced.

 

lestopace_4-1649469586063.png

 

  1. Deselect the Use default gateway on the remote network box and try to reconnect to the VPN.

 

lestopace_0-1649470281921.png

 

Result:

A split-tunnel route has automatically been created to its respective classful address.

 

lestopace_8-1649470057331.png

 

For Windows 11:

  1. Open the search bar and look for the settings:
                                                                            
    Screenshot 2025-01-07 145400.jpg                                                                                      
  2. Go to Network & Internet and VPN:
                                                                
    Screenshot 2025-01-07 145453.jpg                                                                                    
  3. Select the VPN connection and select Advanced Options:
                                                                     
    Screenshot 2025-01-07 145621.jpg                                                                      
  4. On the VPN selected, select Edit on More VPN properties:
                                                                                           
    Screenshot 2025-01-07 145658.jpg 
  5. In the Properties menu, go to Networking, select Internet Protocol Version 4 (TCP/IPv4), and select Properties:
                                                                                  
    Screenshot 2025-01-07 145731.jpg                                                                                 
  6. Once in the Advanced TCP/IP Settings, go to IP Settings and unselect the Use default gateway on remote network option:
                                                                            

Screenshot 2025-01-07 145815.jpg

 

 

Note 1:
This method will prevent the VPN from injecting the default route using the VPN tunnel interface, but it will also not add any other routes that have been advertised using DHCP option 121. To enable split-tunneling to other local subnets:

  • After adding the subnets using DHCP option 121, enable the 'dhcp-ipsec' option in the IPsec phase2 configuration with the following commands:

 

config vpn ipsec phase2-interface
    edit <tunnel_phase2_name>
       set dhcp-ipsec enable
    next
end

 

Note 2:

PPP (Point to Point Protocol) is the foundation for L2TP, which uses IPCP (IP Control Protocol) to negotiate the IP address. Since IPCP historically did not transmit a subnet mask, Windows implemented Classful Networking logic as a fallback mechanism:

  • Class A (10.0.0.0 to 10.255.255.255) Windows adds a route to 10.0.0.0 with a mask of 255.0.0.0 (/8).
  • Class B (172.16.0.0 to 172.31.255.255) Windows adds a route with a mask of 255.255.0.0 (/16).
  • Class C (192.168.0.0 to 192.168.255.255) Windows adds a route with a mask of 255.255.255.0 (/24).

 

If this behavior causes conflicts (for example, if the local network is also using the 10. x.x.x range), check the 'Disable class-based default route' box in the Advanced TCP/IP settings (IPv4) of the VPN connection:

 

L2TP.jpg

 

Related articles:

Technical Tip: Split tunneling on L2TP/IPsec VPN between FortiGate and Windows 10.

Technical Tip: Resolving internet connectivity issues with L2TP.