Currently our COntivity 2700 is running parallel to our PIX FW. The 2700 accepts both BoTs and remote user tunnels. I was not involved in the initial design of the VPN setup and was just wondering if it would be more secure to have the Contivity sit behind our FW instead. Of course then I would have to open up IPSEC through the FW and that might add a security hole there. What are everyone's thoughts on this? Behind FW or parallel to FW? Thanks.