@ShawnL, that’s a bit of a tricky one to achieve, but can be done. There are a couple of ways I can think of doing it. Probably the most appropriate is to have two VLANs, one VLAN is included in the VPN, the other isn’t. Then you just have to make sure that clients are added to the correct VLAN - easiest way is static port assignments (or one SSID per VLAN if using wireless). The other way you could do it is using the Site-to-site VPN inbound firewall to limit the local IP addresses that can access the IP addresses across the VPN - but note that this will drop traffic rather than divert it to the local internet. This obviously relies on having known (likely static} IP addresses.
... View more