Skip to main content

Split tunneling for work from home (WFH)

 

Work from home (WFH) has been implemented by default for many network deployments and many different solutions exist. The common use case is for the road warrior. This describes using softether. (Another alternative is strongswan)

A big problem with VPNs is that most force all connectivity via the path when you are connected. A better option is to use a split tunnel whereby only the office connecivity goes over the VPN and the rest remains on the existing Internet path. This way your youtube, zoom or teams experience remains great and is not influenced by the VPN.

At Fusion Broadband South Africa we have started deploying as using rport. Rport provides a great mechanism to leverage Fusion's SD-WAN for additional infrastructure management.

No alt text provided for this image

The ability of rport can be leveraged to extend and provide VPN services. Although many other variants are supported and can be potentially deployed, a popular choice, as mentioned is softether.

No alt text provided for this image

To ensure the road warrior has the best user experience a technique known as split tunneling is required. This is achieved using RFC3442 for all the routes that are required for office connectivity and work. Then the metric for that network is made higher on the laptop. This now results in only office connectivity going via softtether and the rest on the normal Internet path.

No alt text provided for this image
No alt text provided for this image

The result is a good and stable WFH/road warrior solution.

No alt text provided for this image
 
This article was originally published over on LinkedIn: Split tunneling for work from home (WFH)

Comments

Popular posts from this blog

LDWin: Link Discovery for Windows

LDWin supports the following methods of link discovery: CDP - Cisco Discovery Protocol LLDP - Link Layer Discovery Protocol Download LDWin from here.

Battery Room Explosion

A hydrogen explosion occurred in an Uninterruptible Power Source (UPS) battery room. The explosion blew a 400 ft2 hole in the roof, collapsed numerous walls and ceilings throughout the building, and significantly damaged a large portion of the 50,000 ft2 building. Fortunately, the computer/data center was vacant at the time and there were no injuries. Read more about the explosion over at hydrogen tools here .

STG (SNMP Traffic Grapher)

This freeware utility allows monitoring of supporting SNMPv1 and SNMPv2c devices including Cisco. Intended as fast aid for network administrators who need prompt access to current information about state of network equipment. Access STG here (original site) or alternatively here .