Hello! I want to give support for 7 remote companies (for us implated sw solutions) using DSL links over internet. The idea is to have a central branch VPN server (ISA server) and remote DSL/VPN_routers (HW solutions: Cisco, shiva, Alcatel,...) that establish permanent VPN tunnel (l2tp/ipsec using x509 digital certif) with branch office at the router startup process. At the branch ISA have 3 NICs (private, public, DSL_public (only for support traffic statit routed)) My dubts: 1) Anyone have such solution, ie, a black_box hardware DSL/vpn solution (cisco, shiva, ...) that is compatible with microsoft RRAS (ISA) VPN server. 2) When ISA route to this VPN tunnels. Its first make NAT for public iface and before route to the vpn tunnels, i.e, I need to configure rules at ISA "packet filters" Thanks, Morvan.