I need to make users connected with vpn client to central office's lan, going to internet using the central office's internet connection. I mean wihout having split-tunnel and without using an internal proxy. I would like to know if it is possible with PIX or ASA. I think it's like to tell to have traffic going in and out the firewall using the same outside interface. Thank you very much in advance for your appreciated support.
Yes, definitely can.
You would need to configure the following:
same-security-traffic permit intra-interface
Plus, assuming that you already have "global (outside) 1 interface", you can configure the following:
nat (outside) 1
For example: if the ip pool subnet for the vpn client is 192.168.100.0/24, then the following:
nat (outside) 1 192.168.100.0 255.255.255.0
Hope that helps.