> Source: [sk181416](https://support.checkpoint.com/results/sk/sk181416)

# sk181416 - How to control routing priority in Capsule VPN for Android

| Property | Value |
|----------|-------|
| Solution ID | sk181416 |
| Date Created | 2023-08-24 |
| Last Modified | 2023-09-07 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Android |
| Platform | Mobile Devices |

## Solution

### Overview

An attacker with the use of a specially crafted Wi-Fi network, to which the Capsule VPN for Android app connects, can cause traffic from a targeted source IP address to go outside the VPN tunnel instead of going through the VPN tunnel.

### Prevention

To prevent this type of attack, you can configure the applicable "key-value" pairs in the applicable VPN profile:

|------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Key                    | Description and Values                                                                                                                                                                     |
| `includeLocalNetworks` | Controls whether to include local networks in the VPN tunnel: * `yes` = Include local networks in the VPN tunnel * `no` = Exclude local networks from the VPN tunnel (this is the default) |
| `includeGwRoute`       | Controls whether to include the VPN Gateway route in the VPN tunnel: * `yes` = Include the VPN Gateway route in the VPN tunnel * `no` = Exclude the VPN Gateway route from the VPN tunnel  |

<br />

### Configuration

You can configure these "key-value" pairs in one of these ways:

* Directly in Android on supporting MDMs.

* Through a custom "key-value" pairs set in the VPN profile that you can configure in one of these ways:

  * In MDM deployments, you can configure these "key-value" pairs in the custom data of a "**custom ssl** " VPN profile. See: [sk169755 - Capsule VPN setup through MDM](https://support.checkpoint.com/results/sk/sk169755).

  * For deployments using a QR code for the Capsule VPN app, you can configure these "key-value" pairs with the Check Point "CPQRGen" tool. See: [sk102796 - Creating a QR Code using CPQRGen for Mobile applications](https://support.checkpoint.com/results/sk/sk102796).

<br />

### Related Solution

[sk181399 - How to control routing priority in Capsule Connect for iOS](https://support.checkpoint.com/results/sk/sk181399)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
