VTI can be convenient for remote access usecases as well, and users are familiar with using routing rules for remote access users from OpenVPN interfaces.
Now that we use XFRM interfaces under the hood for VTI it is feasible to bind multiple remote-access tunnels to a single XFRM interface.
As part of this, we should also allow explicit IP ranges to be specified for remote-access pools as the user might want to assign the router an IP on the VTI interface.