Okay, here's an interesting sceneraio we have with our Firebox. We have a vendor who requires we connect to them via a Cisco VPN link using a Cisco 26xx connecting over the internet. The key is this router needs to be on the DMZ port on the firebox and on a seperate subnet from our local LAN. We setup a 1 to 1 NAT for the Cisco router on the DMZ and this can be seen from the internet just fine. When their router tries to connect to the router at our location we are seeing error messages on the Firebox about Masquerading Errors. Anyone have any helpful hints?