Split tunneling in VIA is network based, not application based.
Once the traffic is tunneled to a gateway you can apply application based policies, but unless you know the IP addresses for Office 365 and Windows Update, I don't see a way to send that direct, while tunneling other traffic.
You may have a look at the HPE Aruba Networking SSE product for a more modern approach.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jul 08, 2024 03:30 AM
From: kurtw1
Subject: Internet Split Tunnel Policy Possible?
Yes, I'm aware that split tunnelling needs to be enabled. After enabling split tunnelling, is it possible to apply policies as asked in my original post, or are the rules solely network segment based?
Original Message:
Sent: Jul 04, 2024 09:54 PM
From: ariyap
Subject: Internet Split Tunnel Policy Possible?
you need to first enable split-tunneling which is by default disabled.
its under L3 Authentication->VIA connection->new-profile
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: Jul 04, 2024 09:15 AM
From: kurtw1
Subject: Internet Split Tunnel Policy Possible?
We are implementing VIA for one of my customers and they had a question about using policy for split tunnel rules. In the GUI, it appears that you can only use network IDs to determine whether or not traffic will go directly out the Internet or through the VIA VPN tunnel to the VPNC. They would like to have all traffic going through the tunnel except for things like Microsoft updates and O365. All normal website traffic would go through the VPN tunnel. Based on the output below, it doesn't look like what they are asking for is possible, but I wanted to ask to be sure.