For those who are not familiar with Split-tunneling, the
issue with split-tunning is that your vpnclient is also
exposing itself to the Internet (unless you're also behind
a corporate firewall or personal firewall so that someone
on the internet can potential take over the vpnclient
machine and use that machine as a conduit to the corporate
network. That's why most people prefer to disable split
tunneling which is disable by default on Cisco Pix. If you
want people to have web browsing, I suggest that you go
with Proxy server (i.e. squid or ISA). Enabling split
tunneling, IMHO, is a bad idea.