STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway must disable split-tunneling for remote clients VPNs.

DISA Rule

SV-207243r1005432_rule

Vulnerability Number

V-207243

Group Title

SRG-NET-000369

Rule Version

SRG-NET-000369-VPN-001620

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to disable split-tunneling for remote clients VPNs.

Check Contents

Verify the VPN Gateway disables split-tunneling for remote clients VPNs.

If the VPN Gateway does not disable split-tunneling for remote clients VPNs, this is a finding.

Note: Certain cloud products require direct connectivity to operate correctly. These items may be excluded from the split tunneling restriction if documented and approved.

If split-tunneling for remote client VPNs is enabled by the above exception, verify only authorized external destinations are excluded from tunneling as shown in the example below:

Webvpn
anyconnect-custom-attr dynamic-split-exclude-domains description DoD IL5 Authorized Destinations
anyconnect-custom-data dynamic-split-exclude-domains DoD-IL5 dod.teams.microsoft.us,azureedge.net,core.usgovcloudapi.net,streaming.media.usgovcloudapi.net,wvd.azure.us,cdn.office365.us

anyconnect-custom dynamic-split-exclude-domains value DoD-IL5

If any unauthorized exempted connections exist, this is a finding.

Vulnerability Number

V-207243

Documentable

False

Rule Version

SRG-NET-000369-VPN-001620

Severity Override Guidance

Verify the VPN Gateway disables split-tunneling for remote clients VPNs.

If the VPN Gateway does not disable split-tunneling for remote clients VPNs, this is a finding.

Note: Certain cloud products require direct connectivity to operate correctly. These items may be excluded from the split tunneling restriction if documented and approved.

If split-tunneling for remote client VPNs is enabled by the above exception, verify only authorized external destinations are excluded from tunneling as shown in the example below:

Webvpn
anyconnect-custom-attr dynamic-split-exclude-domains description DoD IL5 Authorized Destinations
anyconnect-custom-data dynamic-split-exclude-domains DoD-IL5 dod.teams.microsoft.us,azureedge.net,core.usgovcloudapi.net,streaming.media.usgovcloudapi.net,wvd.azure.us,cdn.office365.us

anyconnect-custom dynamic-split-exclude-domains value DoD-IL5

If any unauthorized exempted connections exist, this is a finding.

Check Content Reference

M

Target Key

2920