I am interested in hearing the rationale for the different placement of a VPN server in a DMZ. We have two layers of firewalls with VPN capabilities. Do we terminate DMZ at the front or rear of the DMZ? One layer is Internet facing. This protects our external web and email servers. The second layer of firewalls protect application and database servers and remote connections to our internal corporate network. Internet::FW1::Web & Email::FW2::App & DB::Enterprise Network Web, email, App, and DB are located at a hosting facility. Any comments about placement for the VPN server? Within FW1 or FW2? Regards, Brian brian_anon@hotmail.com VPN is sponsored by SecurityFocus.com