Not ideal, but the the client is routing all traffic including internet over the vpn, because it has a route for 0.0.0.0 0.0.0.0 . We should be able to select if possible which routes go over the tunnel, just like with the SSL. [:)]
Yes it is split-tunneling, which I have enabled on all my ASA firewalls at work.
Here is a screenshot showing how I only secure routes for the remote networks, and interntet still goes out locally.
[:S] this means its working and you can select which routes go through the tunnel and which not?