Dialpad is not designed to function over a VPN. If your company uses a VPN, please utilize a split tunnel and direct Dialpad traffic outside of the VPN.
VPNs are usually configured at the headquarters or network branch levels. This security measure prevents unwanted external access to internal company data while allowing an encrypted connection from an external network with the correct permissions.
For example, an employee working from a remote site, remote office, or home can access applications available on the internal company network.
Types of VPNS
There are two types of VPNs:
Software
Hardware
The main difference is that hardware VPNs are physical stand-alone devices that handle VPN functions and are typically installed in a data closet or networking center. Software VPNs are third-party applications that are much more widely utilized today than hardware VPNs. You can install software VPNs on your devices to allow protected access to internal network systems and data, or to allow your network users access to applications on a third-party server.
Split tunneling
If you do use a VPN, Dialpad requests that you utilize a split tunnel configuration.
Split tunneling is a VPN feature that routes specific kinds of traffic directly through your local internet connection and the rest of the traffic through the secure connection back to your company network. Split tunneling features in VPNs typically let you choose which apps to send with VPN security and which can connect normally using the app's security tools. Dialpad has layers of substantial security best practices in use, and VPNs typically add substantial delays in data speeds that interfere with the smooth and orderly transmission of call traffic.
There are typically two types of Split Tunneling VPN features available:
URL-based split tunneling lets you choose exactly which URLs you want to be encrypted through the VPN. This is usually done using a VPN browser extension.
App-based split tunneling works in a similar way, as it lets you choose which apps you want to be routed through your VPN, while the rest of your traffic travels through your regular network.
Vendor-specific configuration guides
Configuring split tunneling varies depending on your network architecture and security vendor. Below is a directory of official documentation from major VPN and firewall providers detailing how to exclude Dialpad traffic using app-based or FQDN/IP-based split tunneling.
Provider / Vendor | Category | Recommended Approach | Official Documentation |
|---|---|---|---|
Palo Alto Networks (GlobalProtect) | Hardware & Software | FQDN / Application Exclusion | |
Fortinet (FortiClient / FortiGate) | Hardware & Software | Split Tunneling (FQDN & App) | |
Zscaler (Zscaler Client Connector) | Cloud / SASE | Bypass / Application Tunneling | |
Cisco Meraki | Hardware VPN | Split Tunneling Rules | |
Surfshark | Software VPN | App-based / URL Bypass (Bypasser) | |
Cloudflare WARP (Zero Trust) | Cloud / SASE | Domain & IP Bypass (Exclude Mode) | |
Cato Networks | Enterprise SASE | Destination Exclusions & Bypass Policy | |
Cisco Umbrella / Secure Client | Cloud / SASE & Software VPN | Dynamic Split Exclude / Tunnel-All DNS Bypass | |
Netskope (Next-Gen SWG / CASB) | Cloud / SASE | Steering Exception (Bypass) & SSL Do Not Decrypt | |
NordVPN | Software VPN | App-based Bypass / Domain Exclusions | |
ExpressVPN | Software VPN | App-based Bypass (Split Tunneling) | |
Proton VPN | Software VPN | App & IP Exclusion (Exclude Mode) | |
IPVanish | Software VPN | App-based & Domain-based Split Tunneling | |
Mullvad VPN | Software VPN | App-based Exclusion / WireGuard Route Bypass |
Important notes
Behavior may differ by product/version/environment
Please work directly with the software or hardware manufacturer for authoritative configuration guidance
Dialpad can provide the required domains / IPs / ports and testing recommendations, but cannot fully advise on or support third-party security/network product configuration.
FQDNs for Split Tunneling
Update your VPN split tunneling settings to include Dialpad’s specific FQDNs.