I would give my eye teeth for these end points, but we don't have them right now. I'm not sure if we ever will, but I am very hopeful.
Are you in a position where you could use RADIUS instead for the client VPN? That can simplify user management, especially if you're working with ActiveDirectory users.