I set up the pix client software, to connect to my 501 3DES. Everything worked great, it connects. Now I want to configure XAuth, and I am am somewhat confused. Does the Radius server use the same username and password key that I gave to the VPNGroup on the pix? My firewall is connected directly to the internet, can I run my IAS server on the inside? I tried to read Cisco CCO docs, and they show the IAS Server on the DMZ. Should the IAS Server always be done on a Member server, and not a domain controller? Any info on XAUTH would be appreciated. THanks in advance!