Hi! I am not quite sure about this terms, but I believe it would be the VPN Gateway. I want the ISA server (RRAS, ISA or W2K server - whatever) to establish a VPN tunnell to an external office. The External office will terminate this VPN tunnell with a Firewall-1 from checkpoint. Then I will have some of my clients having this VPN tunnell as default way out. All the rest(on the same subnet) will connet to the internet directly. Thanks Bjørnar