If access to the corp VPN was functional, it should have nothing to do with the IPsec pass-through options.
Based on other comments here, I am thinking it may be related to the presence of IPv6. Based on the IPv4 routing tables, split-tunnel does not appear to be in place. However if the AnyConnect client isn't forcing IPv6 down the tunnel or blocking it, it is possible that when the client is dual-stacked, it has native Internet via IPv6.
Based on other comments here, I am thinking it may be related to the presence of IPv6. Based on the IPv4 routing tables, split-tunnel does not appear to be in place. However if the AnyConnect client isn't forcing IPv6 down the tunnel or blocking it, it is possible that when the client is dual-stacked, it has native Internet via IPv6.