VPN1 use_range_extension_policy appears to be related to Split Tunneling for Office 365 and similar apps.
More specifically, it allows Office 365 and similar applications to be routed to the Internet while routing everything else to the VPN gateway.
I can see it in an internal SK (sk176303) and, from the SR I was able to find, TAC was who told you about it.
R81.20 has native support for this particular feature and it’s documented in the Remote Access VPN guide: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
In previous releases (R80.40 - R81.10 with appropriate JHF), the procedure must be requested from the TAC.
Now, to your specific issue: I suspect this particular parameter was only tested for the use case it was intended (dynamic split tunneling).
From reading your TAC case, it doesn’t appear TAC gave you the full procedure.
Please request from TAC the full procedure from sk176303 and ensure the appropriate IP addresses are not excluded from hub mode.
Otherwise, I can only suggest to continue working with TAC on this.