Kamikaze,
Thanks for the info, I tried the fix (haven't yet worked out the templates to make the config permanent) and I can now give specific IP's to vpn clients so at least we can audit their trail. Having said that, I tried to amend the firewall following that syntax but it allows connectivity to all internal ip's. Any ideas where I might be tripping up? The details I applied were.....
Int SME i/f 192.168.143.1 so trusted vpn network is 192.168.143.0
Client fixed address is 192.168.130.226 so they are not on the same subnet
Any more idea's
Thanks in advance