David, Thanks for pointing to me what I overlooked, even though I read it in one of Tom Shinders tutorials I have been getting a lot new information very fast and lost that detail. Yes, the entry point question is a dilemma. I could have the client configured with a personal firewall but there is no way to enforce the continued use. This is where FW1-Securemote has an advantage of MS-VPN. With that product you can maintain a remote security policy on the clients. Thanks once more, Brian -----Original Message----- From: David Haam [mailto:DavidH@xxxxxxxxxxxx] Sent: Tuesday, April 23, 2002 1:57 PM To: [ISAserver.org Discussion List] Subject: RE: [isalist] VPN Client cannot access the Internet? http://www.ISAserver.org This is a multi-part message in MIME format.