I have a very similar problem as well. I have 2 - 1811's with a tunnel between them. I am not using crypto maps but rather VTI with IPSec. I can ping, FTP, etc., but drive mapping fails, outlook doesn't connect - basically any connection to a Microsoft resource fails. BUT, if I take the test windows account and elevate it to a domain admin, everything works. I've verified this many times and can reproduce it every time. Regular user status, no go. Domain Admin users connect ok. I don't think it's a Cisco issue but rather a Microsoft focus but they have nothing on their support site about this. Any one have any ideas? BTW, Lorenz, give my test a try and see if you get the same results.