I was setting up a VPN gateway using a RHEL5 server the other day only to find that a majority of the features that you really need to have a functional Site-to-Site VPN gateway aren't included in the version of the ipsec-tools included with RHEL5. One of the biggest features that I found lacking that I just couldn't do without was
split_network under the mode_cfg configuration section. Per the racoon man-page, the split_network feature allows for setting: