I just tried this in the lab and when I selected in global properties to "configured on endpoint client" and pushed policy, option on gateway under vpn clients -> remote access -> allow vpn clients to route gateway through this gateway did not change, it was unchecked. Logically, to me anyway, though I could be wrong, appears that both options would need to be selected for this to work. So, say even if you checked yes for hub mode in global properties, you still may have to enable the other option I mentioned for this to work 100%.