I had a VPN solution working well with a 501. I added two internal remote sites, and added the networks to the no-nat access-list. As soon as I did, split tunneling from the VPN stopped working. No other changes were made. Any suggestions would be appreciated.