Is it possible for a VPN Client user to access the Internet when the VPN Router is not the Internet Gateway. I got this to work by using a Proxy Server, but I'd rather not do that.
OK - based on the equipment you have and the current topology, in my opinion your best bet is to continue with the proxy server. This will also give you control over what users can access while they are also connected to the corporate network which is no bad thing.
There may be something that you could do with Policy Based Routing based on using the source addresses of the VPN pool, but this starts to become messy.
Unless there is a neat way of enabling hairpinning in IOS, as is available on the ASA, I would stay with the proxy server.
Hope this helps?