Hi,
What is your head end RAS device? Based on your head end RAS device...
1. You need to create hairpin vpn config for remote user subnet to access BOs.
2. Make BO subnets added to 'Spilittunnel' list for remote access users.
3. On head end and BO devices make sure the traffic to & from remote user subnet is not nat'd.
Check the below doc for hairpin config example:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00805734ae.shtml
hth
MS