Coming over from the Citrix side where we used a Netscaler and AD to create a policy that required you to be a member of a named AD group in order to access externally. The Netscaler would be similar to the HALB but a bit more advanced. You can look at this 2 different ways, 1 is to "allow" a group of users in from home, or "prevent" a group of users to access this from home. The reason being is that we will be using RAS for some shop-floor generic logons and cannot change those passwords every time an employee leaves the company so we need to prevent them from accessing RAS from home. "home" would be anywhere or any network that is not on our LAN. I do not want to use MAC, IP, or client name for filtering. I need to be able to authenticate the user either at the HALB or the next component down. I would prefer if I could have all 4 of servers in the same site. Currently we are trying to do this by using 2 sites but the way Parallels RAS Console shows all of the published apps regardless of site, it gets a little ugly. I guess if it comes down to it... the remote user could log on using SSL VPN, then connect to the RAS.