Versions 4.1.5 and 4.1.6 of WebVPN work fine in this case: the basic authentication pop-up message of the internal websites (IIS, apache) gets replaced by an HTML form on the WebVPN page where you would enter the username/pass of the internal web site as normal.
Interesting thing: in case when the internal web site has an SSL protection and the certificate has expired, the WebVPN won't let you login into this site