I've got a main site, this site uses a pix to protect from the internet. Also on this main site is another pix which connects/protects the site from the WAN. We have a remote site, also with a pix protecting from the internet. We have created a site to site ipsec tunnel between the main office internet pix and the remote office internet pix. Now, a client at the remote office needs to use a VPN client to connect to some vpn server on the WAN of the main office...so through the vpn tunnel, and out the pix at the main site protecting from WAN and into some vpn server. From the remote site to the main lan, no problems, full communication, but when the user tries their vpn client, no luck. Is there some issue with using a vpn client THROUGH a vpn tunnel. I'm 99% sure that all of my nat and crypto lists are ok...thanks for any help.