Hi Greg, You can do it, but you'll have to use packet filtering instead of publishing rules. You can only publish TCP and UDP protocols, and PPTP requires GRE. You can't publish L2TP/IPSec because the NAT breaks the IPSec component, so you have to use packet filtering "publishing" for that too. HTH, Tom Thomas W Shinder www.isaserver.org/shinder <http://www.isaserver.org/shinder> ISA Server and Beyond: http://tinyurl.com/1jq1 Configuring ISA Server: http://tinyurl.com/1llp <http://tinyurl.com/1llp> -----Original Message----- From: Greg Mulholland [mailto:greg_mul@xxxxxxxxxxxxxxx] Sent: Sunday, June 29, 2003 6:20 AM To: [ISAserver.org Discussion List] Subject: [isalist] RRAS and vpn http://www.ISAserver.org Hi guys Wonder if anyone can shed some light on the possibilities of running an rras server for vpns behind the isa machine. This is not my flavor of choice but I am researching a scenario in my head. I can find little material that is relevant to my question and I suspect Tom will be able to answer it in a flash but, if anyone else is awake and knows the limitations I would appreciate it. Thanks Greg Mulholland Tech Services Manager Harvey Norman +613 98019333 greg_mul@xxxxxxxxxxxxxxx