I have set up an ISA server on a Win2000 RRAS server with a VPN device(also set as external NIC IP gateway) connected to the external address. The VPN gateway will allow traffic through from remote subnet(internal IP addresses). NAT is enabled on ISA server to allow for SMTP traffic to be routed to mail server. HTTP and SMTP goes through OK What do I need to enable/configure on ISA server for it to recognise even a ping from my main internal network to reach VPN device which will know what to do with it, and to allow remote subnet traffic to get through. - or is the problem in my routing table on this server? It does contain the route[remote subnet IP, subnet mask, VPN device IP, external NIC] Henri