If you configure the tunnel to search the client's dns entries second, and have the appropriate list of dns suffixes configured, would this solve your problem? This, of course, assumes that both your internal dns domain and that of your customers are different. If you both use .corp.local, I don't think there's a solution. Also, beware that poorly configured Cisco VPN clients can break even this configuration because they sometimes don't remove the dns suffixes when the Cisco VPN exits.
... View more