Thx all of you.

Please let me to conclude what we have tried and worked:
1/ The splitting tunnel is
NOT only work for the same subnet, if your sslvpn cllients are assigned another subnet other than your office one, it also works~
2/ If you want to
REDIRECT ALL TRAFFIC from your sslvpn clients to your company network and let the Internet traffic going thru your compan' s Internet connection, you need to leave the ' use remote gateway..' option as default (checked) on your fortissl adapter, and then create an dedicated port2-to-port2 (wan-to-wan) fw policy to allow the sslvpn subnets (hosts) accessing the Internet.
3/ If you assign another subnet for your sslvpn client other than your office internal subnet(s), it' s
NOT necessary to set the secondary ip on your FG box' s internal interface~
4/ Even in v3.0mr1, there is no splitting tunnel mode, you can still split the normal Internet traffic (using your local Internet connection) and the sslvpn encrypted traffic to your office internal networks (via the sslvpn tunnel) - Just
uncheck the option of ' use remote gateway...' on your sslvpn adapter.
Pnelson: Please refer to above point 2 in your case, it should works for you!