We are beginning the process of migrating from a Windows 2000 RAS VPN server to using PIX firewalls and Site-to-Site VPN tunnels. Currently each of our remote users connects individually through the the Windows 2000 VPN client to the RAS Server. Our intention is to put each of our outer offices behind a firewall and create a distinct local subnet for the office. I have been able to establish connectivity from one of the sites, the problem starts when I try logging on to the domain (192.168.0.0) from a subnet(192.168.9.0) outside the subnet the AD's are located on. I have added the subnets to the site in AD Sites and Services, what am I missing?