Now that we have trusted wireless networks, we want to be able to
allow hosts to use dynamically assigned addresses on those networks
and still claim their stable VPN addresses (e.g., for centralized
management). For this to work, the internal endpoint of the VPN hub
has to be outside of the internal network range.
This is currently especially broken for radius, since it's the main
router in the house network.