Created on
10-11-2021
07:43 AM
Edited on
11-26-2025
10:05 PM
By
Jean-Philippe_P
Description
This article describes how to set up split tunneling on an L2TP/IPsec VPN between FortiGate and Windows 10/11.
FortiOS does not support split tunnelling unless FortiClient is used.
To enable L2TP split tunnelling directly in Windows 10/11 host: Technical Tip: How to enable split-tunnelling in Windows 10/11 (L2TP/PPTP VPN)
Some users have mixed environments, and it is necessary to be able to utilize the OS native VPN client.
Related documents:
IP to HEX: https://codebeautify.org/ip-to-hex-converter
HEX to IP: https://codebeautify.org/hex-to-ip-converter
Decimal to IP: https://codebeautify.org/decimal-to-ip-converter
Scope
FortiGate v7.0.1 and above.
Solution
L2TP VPN over IPsec is still used in many environments, and some users want to have split tunneling when L2TP VPN over IPsec is configured.
If the traditional way is used, the configured L2TP range can access only IP addresses from that range, because the Firewall does not provide additional routes.











Subnet Mask (in CIDR notation) – Specifies the prefix length (e.g., /24, /16, /8).
Destination Subnet – The network address corresponding to the prefix length.
Next Hop – The gateway IP address the client should use to reach the destination subnet.
Windows 10 output:
If, after connecting to the L2TP VPN, the routes are not shown, one possible solution would be to try splitting up the networks.
For example, the following route is being pushed 172.16.1.0/22 via 192.168.89.1, the hex should be '16AC1001C0A85901'.
If this is not working, try pushing routes for:
In this case, the hex value for the DHCP Option 121 will now look like '18AC1001C0A8590118AC1002C0A8590118AC1003C0A85901'.
Related article:
Technical Tip: How to connect Windows 10 client to L2TP VPN network
Note:
In some scenarios, configuring split tunneling may result in clients losing internet connectivity via their local NIC adapter. To troubleshoot this issue, inspect the routing table on the host after establishing the L2TP tunnel connection.
Verify that the route is directed to the local adapter. If the default route points to the L2TP tunnel instead, review the following configuration settings in the L2TP tunnel adapter:
Once the change is made, the L2TP connection must be re-established for the changes to take effect.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.