I run a large wan for 18 school districts. Each has a few public IP's on their router and Nat 10.x, or 172.x private addresses . I am getting request to allow vpns to each school's local network, which I am not against, but I want full control of what can and cannot be done. A vpn from a single workstation connected to the schools LAN is not a big deal to set up, but I would like to set up a server inside the WAN that users would have to authenticate to, and then send them on to their destination. This would require some sort of vpn to all the schools from this server. Is this something that can be done, or do we need to do a point A to B setup rather than A to B to C? Raymond _______________________________________________ TCLUG Mailing List - Minneapolis/St. Paul, Minnesota http://www.mn-linux.org tclug-list at mn-linux.org https://mailman.real-time.com/mailman/listinfo/tclug-list