The per app tunneling solution implements app-level access controls to your network. Traffic from apps is routed through the native framework and arrives at the VMware Tunnel client as data streams. The data streams pass through the same channel as a full-device VPN does and arrive at the Tunnel server. On the server side, the server opens a TCP connection for each data stream and the data is sent to the destination host through the data stream. Once a connection is made, data can continuously flow between the client and host until either side drops the connection.