HI there
When a macine is VPNed in to a Headend device or a VPN gateway without split tunneling, the client machine is only visible to the internal lan to which the client os connected.
Anyone else from outside cannot peep into the machine.When you do traceroute to the VPN gateway IP without being VPNed in you would see many hops. But when you are VPNed in you would see only one hop.
Enabling Split tunneling does modify the routes on the machine. So whenever it has to go to the Local networj you are trying to reach it would go throught the VPN getaway othetwise would go through the nomal default gateway (for normal internet traffic). This allows the machine to be visible to the internet if it is not behind a firewall or a NAT/PAT deivce.
In case if you want to access the ionternet by sending all traffic to the VPN gateway and the gateway taking care of the rest of the routing to the internet, it is possibel if you have the VPN gateway or headend as a router or a conc and not a PIX.
Hope this helps
Thanks
Wakif