When you configure a split tunnel to include
all traffic—IPv4 and IPv6—based the destination domain and port (optional)
or application, all traffic going to that specific domain or application
is sent through the VPN tunnel for inspection and policy enforcement.
For example, you can allow all Salesforce traffic to go through
the VPN tunnel using the
*Salesforce.com
destination domain. By
including all Salesforce traffic in the VPN tunnel, you can provide
secure access to the entire Salesforce domain and subdomains. You
can configure a split tunnel without specifying a destination IP
address subnet, which extends the split tunnel capability to domains
and applications with dynamic public IP addresses, such as SaaS
and public cloud applications.