ISA 2004: I have a VPN server sitting behind Windows 2003/RRAS (network behind a network) -- the Win 2003 is SNAT with the ISA 2004. Internally, the device, wireless remote access point (RAP), attaches to the VPN server routing through ISA with no problems. ISA's logging displays NAT-T client (4500/UDP - send receive) as the protocol used. How can I publish this VPN server/protocol to the Internet? The VPN server sees the Internet based RAP - I determined this by pinging the RAP from the VPN server while they are negotiating. Their negotiation never comes to fruition. The RAP just reboots and keeps trying. Now, this published rule to the Internet uses (NAT-T server receive send) protocol - not the (receive send) as seen internally. TIA greg