Hi T Ken,
For a Windows VPN profile, add the organization’s internal subnet prefixes to the VPN RouteList so traffic to those networks is routed through the VPN tunnel. For example, use Add-VpnConnectionRoute -ConnectionName "VPN-Name" -DestinationPrefix "10.20.0.0/16" for each required subnet. Verify the routes with Get-NetRoute or route print after connecting. Also ensure the VPN gateway has a valid return route to the VPN client address pool; otherwise, the connection may still fail even with the correct client-side routes.
Harry P.