If you are using the "Enabled Based on Policy Destination" then your
policy ID 2 has to have your specific subnets on your lan defined in the
destination section. If you have all, like your image shows, then the
split tunnel will match on every IP an...