in the global properties you set the "route all traffic to gateway" to "configured on endpoint client" for oth the secureclient mobile and endpoint connect options
on the gateway object you tick the box for "allow vpn clients to route traffic through this gateway" and you configure the remote access encryption domain for the split vpn users
if the end user connects once to the gateway, the setting to route all traffic to gateway will no longer be greyed out and the user can freely choose between full tunnel or split tunnel
you could create a new vpn package one for full tunnel users and one for split tunnel users and install accordingly, that way you don't have to teach them about the setting
download the tool from sk122574
i believe you need the setting "neo_route_all_traffic_through_gateway"