I would think there would be examples of this out there, but I haven't been able to find them if they do exist.
I have a 2610XM that creates a secure tunnel over a dial-up connection with a W2K machine running Cisco's VPN client. My problem is this: Traffic to the internal network does not *have* to be encrypted. Users can disconnect the VPN if they choose to press buttons.
I tried creating an ACL and adding it to the crypto map with a "match address" (see attachment) but all I've managed to do is prevent the VPN from being established.
The attachment includes the IPSEC debug comment and the running config.
TIA,
Martin