Using an Office Mode IP that is included in the local VPN encryption domain should provide what you want - but this is standard only with CP GWs. If this was a centrally managed SMB GW, you could just use RA VPN with Hub Mode. With locally managed SMB, you will have to manually configure a local encryption domain including the networks behind the Cisco GW for remote access users: See Check Point 1400 Appliances Locally Managed Administration Guide R77.20.87 p.158 !
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist