I am trying to establish a new VPN connection from outside the office so that users can VPN to the internal network. I would like the users to be authenticated via the domain controller (Win 2003 Server) running AD. I don't know where exactly I'm having problems, but I am very confused about how to set up the tunnel initially. The tunnel would need to reach out public IP, which I believe is either our Netopia router or the serial IP from our service provider. It then needs to travel through our Netscreen firewall to be authenticated via the domain controller. My problem right now is that I can't seem to get through the firewall, but I'm not sure if I also need to set up a static route on our Netopia router. Any basic help to get this "kickstarted" is greatly appreciated!