I am replacing a 2600 with a 2820. We use bt business as our ISP and have multiple public addresses so use the LAN "2nd ip address" and "vpn 2ndsubnet on" feature to set the public address of the router for VPN.
I can receive VPN calls from the Internet, and tunnel them onto the 2nd ip address but outgoing tunnels are originating from the the dynamic wan address and NOT the 2nd ip address. The 2600 originates the tunnel from the 2nd ip address correctly.
PS: This has now been worked round you do not need to use the 2nd subnet for outgoing vpn as the 2820 supports putting the bt business router fixed ip address in the WAN1 Internet PPOA configuration page.