Yes, so if you NAT'ed / PAT'ed your VPN range to 172.16.1.x subnet you wouldn't need to change gateway on your laptop as traffic was sourced locally from connected network on the ISR.
Well NAT'ing VNC traffic from VPN client range (or even your specific address) to connected network of ISR and 3560 (172.16.1.x) would solve this. Asuming VPN router's primary path for 172.16.1.x network is via ISR and not 881, also assuming you have...