To decrease load on a VPN Gateway, you can exclude traffic for SaaS from your Remote Access VPN An encrypted tunnel between remote access clients (such as Endpoint Security VPN) and a Security Gateway. Tunnel in Hub Mode.
Chain of Events:
Administrator configures which services to exclude from the Remote Access VPN Tunnel.
The VPN Gateway dynamically fetches the IP addresses of configured services from the Internet, and sends this information to Remote Access VPN clients.
Remote Access VPN clients exclude traffic for these services from the Remote Access VPN Tunnel.