With the latest VPN plugin present the older DNS behavior is restored and the DNS/WINS server addresses would be 172.0.0.1 for any Intranet IP subnet i.e. 172.16.177.28/255.255.255.0 rather than having 172.16.177.1 as DNS/WINS server IP addresses.
EnableADCNetmask is the registry key that will revert the behavior again to use new DNS/WINS server IP addresses.
On the affected plugin, you can create the following registry and that should resolve the issue –
Registry Type : REG_DWORD
Registry Name : DisableADCNetmask
Registry Value : 1
Registry Path : HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Secure Access Client