Hi @OSPF71,
If you go to Security Appliance/Teleworker Gateway > Configure > Site-to-Site VPN, there is a section called VPN settings. As long as the vLAN is set to yes in the Use VPN column, then the vLAN will be reachable when using Client VPN.
If you wish to change that (i.e you only want VPN to access certain subnets at different MXs across your organization), you will need to add additional rules in Site-to-site outbound firewall at the bottom of the same page.
Finally, if you want the client VPN to only access local subnets, set the Use VPN setting to no.
Found this helpful? Give me some Kudos! (click on the little up-arrow below)