Kadu,
Please check if the VPN tunneling is enabled on your EndPoint Security clients, else you are looking at the split tunnel scenario, where not all traffic is being sent to the gateways.
Since you have mentioned that you can ping all the sites, (I presume from the client), try traceroute from the client to determine if your ICMP traffic is going over the VPN, or if it is going directly via local gateway of the remote client.
Additionally, it is a good idea to determine, using nslookup, where does the DNS resolution happening, locally or via VPN.
Next, confirm that you are offering "Office Mode" to remote users.
If yes, check the IP Pool that is being used for address allocation.
Make sure that you have a rule allowing the IP pool to access Internet and that it is being NATed on its way out.
You may also check "Optional Parameters" in the "Office Mode" to see what DNS servers are defined for remote clients.
Cheers,
Vladimir