## TL;DR
Route video traffic outside the tunnel with split-tunnel exclusions. List the video apps (Teams, Zoom, Webex) or their destination ranges as exclusions in the always-on VPN profile, push the profile through your MDM or GPO, and re-test a call. Hairpinning real-time media through the VPN gateway is the usual cause of the lag.

## Steps
1. Decide the exclusion method your VPN supports: per-app exclusions (cleanest) or destination IP/FQDN exclusions. Expected: you know which one before editing. Per-app is easier to maintain; destination lists need updating when vendors change ranges.
2. For per-app: in the VPN profile, add the video apps to the exclusion list. For the Windows built-in client this is the app-based split tunneling list in the Intune VPN profile; for third-party clients it is the split-tunnel exclusion setting. Expected: the apps are named in the profile.
3. For destination exclusions: add the vendor's published media ranges. Microsoft publishes Teams and Microsoft 365 endpoints; Zoom and Webex publish theirs. Expected: the ranges are in the exclusion list. Subscribe to the vendor's change feed so the list does not go stale.
4. Push the updated profile to a test device and join a test call. Expected: call quality is clean and the VPN still shows connected. Verify the exclusion actually applied by checking the client's split-tunnel status page.
5. Roll the profile out to the fleet. Expected: video-call tickets drop and the VPN gateway load falls noticeably.

## Use this when
- Video calls stutter or drop on always-on VPN but are fine off VPN
- The VPN gateway is saturated and media is the biggest flow
- Users ask why calls work at home but not on the corporate profile

## Not for this skill when
- The VPN will not connect at all (tunnel issue)
- Call quality is bad off VPN too (network or app issue)
- Policy requires all traffic inspected (then exclusions are a policy decision, not a config fix)

## Compatibility
- Windows built-in VPN client via Intune, plus major third-party clients with split-tunnel support

## Variants
### Exclusions work for Zoom but not Teams
Teams is a bundle of services (chat, media, signaling). Excluding only the media IPs leaves the rest tunneled, which can still hurt. Use the vendor's full "optimize" category list.

### Security team pushes back on exclusions
Offer the compromise: exclude only real-time media, keep signaling and file transfer in the tunnel. Most DLP concerns are about files, not voice packets.

## Why it happens
Always-on VPN defaults to full tunnel: every packet goes to the gateway and back. Real-time media hates the extra hops and the gateway hates the bandwidth. Exclusions are the standard escape hatch, not a hack.

## Edge cases
- Vendor IP ranges change. Stale exclusion lists silently stop working; review them quarterly.
- Per-app exclusions on Windows need the app's exact executable path. Store apps update paths; re-check after major app updates.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_9H2u6sJSVtAYQlXLaTMcMg
