It seems that if vpn client comes from default External network, everything works fine on ISA2004. When I define an external network X with some specific address subset, firewall denies connection to port 1723 (pptp) even if I make sure that network X is checked on the list of allowed source networks. If vpn clined is coming from X it gets denied right from connection to local host port 1723. As soon as I remove this specific network and client becomes part of default External network, VPN connection works like a champ. Any ideas, please, I am at the end of the rope here.