This is the network setup: Internet => cisco asa => hp switch => lan hosts.
Local machines can get to internet and can access one another. Servers are on 10.40.1.x,
Clients on 10.40.4.x /16, Servers on 10.40.1.x. The asa is not the gateway, the gateway is 10.40.1.1 which is a HP Procurve 2610 (J9088A).
When connecting with cisco ipsec client addresses in 10.40.101.x / 16 are given. The vpn clients can not get to lan machines or servers. The vpn clients can ping the asa and ping the switch at 10.40.1.1. The switch can ping a 10.40.101.x addess (vpn client) and the asa, however the asa cannot ping the vpn clients.