I'm configuring an ezVPN client (IOS 12.4.(15)T to connect to a VPN 3015 Concentrator (4.1.7Q). I have configured "mode network-plus" on the client in order to request an additional IP address to assign to a loopback interface, in addition to the local LAN subnet. This does appear to work, as the correct IPSec SAs are generated and stay active on both sides of the link (one for the loopback and one for local LAN access).
However, the VPNC only shows a route for the local LAN subnet and not the loopback, and so RRI is not injecting the route for the loopback (even though the SA is active). Is this a feature limitation of the VPN Concentrator?