Alain, that is not quite correct. The "directly connected" routes will be used/tried first before the static routes come into play. So the PC's that are connected through the Easy Vpn connections will be routed to first, if none can be found then only does it get routed to the static routes. This is a simple form of fail over and is working quite well for us.
Someone made a change to the crypto acl on the main router and changed the mask from 0.0.255.255 to 0.0.0.255. I am not entirely sure why it only affected a select few of my clients, but at least everything is working now again.