I am setting us a Windows 2008 R2 Rras server on internal network 10.70.0.231 there is a DC running with DNS and DHCP on 10.70.0.230. Users are assigned 10.70.0.50-100 when connecting to VPN in RRAS. Once connected user can ping anything on the 10.70.0.x network and resolve internal and external DNS information. They can not however route to internet sites. Usually i would split the tunnel but that is not what the client wants. The RRAS server has just one NIC installed.
Remote user -> Home router -> Public IP on firewall -> Internal ip RRAS