The answer is very useful, but is that it?
what happens when you follow standard practice and split out routes for IP phones voice subsets from data service - does that cut the number of supported site by 50%?
The routing table needs to handle more than just Auto VPN
- IPSec tunnels are going to need a WAN subnet as well as a target for far end LAN
- static routes or
- dynamic routes pointing for BGP / OSPF
or do any internal routes really reduce the number of tunnels available?