It looks like to me that somehow when users are VPNd in they are still resolving DNS from their ISP DNS. I am affected at home as well. When I ping an internal box via "ping tatl0s11" it adds the suffix and then tries to ping via the internet. I had to create a host file entry to get my firewall client to reach isa. I am not sure what has happened. Nothing changed that I can recall... event logs look normal. Rebooted client boxes, reset routers, etc. Any thoughts as to where to start looking are appreciated.