Datasheet | Smart Split Tunneling from Check Point's SASE

Datasheet | Smart Split Tunneling from Check Point's SASE

Smart Split Tunneling from Check Point’s SASE automatically routes traffic to optimize both security and the user experience, while leveraging FQDNs to increase efficiency.

Datasheet | Smart Split Tunneling from Check Point's SASE

Smart Split Tunneling from Check Point’s SASE

SMART SPLIT TUNNELING FROM CHECK POINT'S SASE | 2

Remote users need secure access to corporate resources, but forcing all their traffic through an encrypted tunnel can cause unnecessary latency. Even with a robust global network this impacts performance and hinders productivity.

When end users are frustrated by latency, they may disconnect from the network to improve internet throughput, circumventing the organization’s security controls.

Split Tunneling Often Falls Short Many remote access solutions offer split tunneling to address this issue, but the configuration settings are often not intuitive. This can result in all traffic still being sent through the tunnel by default, which impacts productivity and user experience, or routing all traffic directly to/from the internet without any security controls, exposing the network to malware and other risks.

A common approach to split tunneling is to exclude specific IP addresses from the VPN tunnel, but this is difficult to manage. Split tunneling by IP is often done with address ranges–a shorthand method for specifying groups of consecutively numbered IP addresses such as 3.7.35.0, 3.7.35.1, 3.7.35.2, etc.

Split tunneling for a single service could mean listing dozens or even hundreds of IP ranges. In addition, you have to update your exclude list whenever the service adds new IPs or removes old ones. That means a long, tedious practice with no end in sight.

Streamline Administration and Improve User Experience Smart Split Tunneling from Check Point’s SASE automatically routes traffic to optimize both security and the user experience. It intelligently routes traffic to private company resources through the encrypted connection while allowing internet-bound traffic to exit directly. This configuration can be set up automatically during network setup using the streamlined management UI, simplifying the admin experience.

Additionally, instead of split tunneling by IP, Check Point’s SASE leverages fully qualified domain names (FQDNs), which are domain addresses with a prefix (subdomains in most cases) such as outlook.live. com or mail.google.com. FQDNs are the ideal choice for split tunneling since a handful of domains can cover an entire service.

SMART SPLIT TUNNELING FROM CHECK POINT'S SASE | 3

Features & Benefits • Simplified administration - Automatic configuration streamlines the admin experience while

leveraging FQDNs avoids the headache of managing IP lists

• Seamless migration – Existing configurations are updated with the latest capabilities without disruptions

• Improved end user experience – Automatic traffic routing results in less latency and faster performance

Meet Check Point SASE 10x Faster Internet Security | Full Mesh Private Access | SaaS Security | Secure SD-WAN Check Point’s SASE is a game-changing solution that delivers 10x faster internet security, SaaS Security, and full mesh Zero Trust Access and optimized SD-WAN performance—all with an emphasis on streamlined management.

Using Check Point’s SASE, businesses can seamlessly build a secure corporate network over a private global backbone. The service is managed from a unified console and is backed by an award-winning global support team that has you covered 24/7.

Check Point’s SASE is part of Check Point’s Workspace Suite, which helps organizations of all sizes secure their workspaces with a suite of products covering network security across browsers, devices, and cloud.

To learn more, visit https://www.checkpoint.com/harmony/sase/ or schedule a demo. To learn more, visit https://www.checkpoint.com/harmony/sase/

Book a Demo

www.checkpoint.com © 2025 Check Point Software Technologies Ltd. All rights reserved.

https://www.checkpoint.com/harmony/sase/ https://www.perimeter81.com/demo-cp?utm_source=cp&utm_content=DTS&utm_medium=PDF&utm_campaign=GenAI-Protect-CP-SASE


Item Type: pdf