@geqian_007 Enable VPN tunneling option on the user role (general tab) and configure the supporting policies under users >> resource policies >> vpn tunneling >> access control (control the traffic allow/deny), connection profiles (IP scope, encryption&transport type, etc.), split tunneling (name implies :) )
... View more