We have a third party firewall VPN appliance made by Netscreen (now Juniper). It serves a half-dozen VPN sites. Now we have installed an ISA 2003 server. Is it possible to establish an IPSEC tunnel between an ISA server and a third party device? Two things I have noticed are quite different. The Netscreen's VPN setup asks for an SPI (security policy identifier). There is no place to put such a thing into ISA, is there? Secondly, my VPN site is a subnet of my 10.* network. The corporate network is 10.0.0.0/20. The branch office is 10.0.144.0/20. When I try to put this address range into ISA, it complains because it thinks the branch office subnet overlaps with the corporate LAN, because both are on 10.*. This seems silly to me.