Hi there Roh_oh. Unfortunately there isn't a way to do this yet. We face the same issues you are. I think CP sort of has the logic backwards with the current solution. Ideally, with a split tunnel the default should be "Internet" and not "on prem". Only go back to "on prem" for applications/sites that you want. Our RAC is fairly large these days, and we have a few sites that we cannot get static IP's or network ranges for. We have worked around by using published MS Edge shortcuts in Citrix.
We are looking at CP Harmony Connect soon, and may route all traffic through this and hopefully will get a range of static IP's that remote sites can then filter on.
As far as Salesforce, we have a range of IP's for Salesforce, so you might be able to get that range added to your RAC.