Version 3.x of the client inserted a kernel-mode shim in the TCP/IP stack that
let the client bypass the routing table. Version 4.x supposedly does away with
that idea and uses an NDIS4 virtual adapter, so maybe it's worth a try.
Quoting Steve Feehan <[log in to unmask]>:
> Can't this "split tunneling" thing be accomplished
> via routes? That's the way I do it using vpnc.
> And you've got my vote for using an "open" VPN. Or even
> better, allow individuals or groups to provide their
> own VPN. Last I checked, the IPSec protocols were
> being blocked at the border.