I have a Checkpoint FW setup in front of an Nated ISA2004 VPN server
with 2 Nic's installed the problem i am having is when a Remote VPN
Client vpn's into the ISA 2004 server they can browse the network
without any issues however if the same client wants to goto the
internet while connected to the VPN it seems as thou the ISA 2004
server is not routing them back to the Checkpoint FW to goto the

Config is as follows.

--->Remote VPN Client-------->Checkpoint FW -------->Nated ISA2004 vpn
Server -------LAN

On the ISA 2004 server both Nic's have an internal address assigned to
them however one of those are Nated from the Checkpoint FW.
I think the issue maybe when you put a rule in the ISA2004 firewall to
allow internet browsing you say go to external yet both nic's are
technically internally defined.How can you tell the ISA 2004 server if
you can find the address reroute it back to the Checkpoint FW.

These are examples only not true settings
( Nated to internal address of Called External
Nic#1 allowing only PPTP No Gateway on Nic)--(Nic#2 Called internal is
addressed with a Gateway of Checkpoint FW).
The Network of is defined as internal in the properties.
Basically how can i have a Nated ISA2004 server behind a different

Hope i explained it ok..

Thanks in advance.

