I'm sure this has been answered before, but I can't find any up to date responses. I'm still using ISA 2004 for inbound VPN connections from my users. While they are vpn'ed in, they are unable to surf the internet. I understand the risks, but is everyone allowing it now-a-days? Our guys constantly need to get on the internet. Is there something I can enable on ISA to allow this or do they have to make the change on their vpn connection to allow split tunneling?