DirectAccess clients use split tunneling in the default configuration, enabling them to access the Internet directly while at the same time being connected to the corporate network. This configuration is efficient, but it introduces some potential security risks that can be mitigated by enabling force tunneling.
How It Works
With force tunneling enabled, the Name Resolution Policy Table (NRPT) is configured to send DNS requests for all namespaces to the DNS64 service on the DirectAccess server. This differs fundamentally from split tunneling, ...