This issue arises because when you configure the IPSEC tunnel, the LRT214 fills the originating address for you based on the actual address of the host (i.e. the subnet private address), and you cannot change it to the public IP address of the parent router. 1. Change them to a unique subnet for the client VPN. 2. If still problem, set them up as split-tunnel if they're on Win10. I have scripts in my signature that you're welcome to grab and butcher. 3. Verify again that nslookup/dig is resolving to the correct IP for their mailserv. KB ID 0001503. Problem. With the newest version of AnyConnect (4.7) there’s an added feature called ‘Management VPN’. It’s there, so that if you have remote users who don’t VPN in very often, then you may struggle to mange them, e.g. put software updates, AV updates, SCCM packages etc. down to them.