Hi, I'm trying to build a VPN tunnel from an internal Win2K machine to a server on the Internet (also MS). We are using a SuSEfirewall2 (SuSE 7.3) to protect our internal Lan. The internal Lan is masqueraded. Is there a way to configure the firewall to allow VPN connections from the Win2K machine? I opened the following ports in FW_MASQ_NETS: 10.0.0.0/24,0/0,tcp,1723 10.0.0.0/24,0/0,udp,1723 10.0.0.0/24,0/0,tcp,47 10.0.0.0/24,0/0,udp,47 10.0.0.0/24,0/0,udp,500 This didn't work. I read somewhere that the communication over port 47 is not tcp or udp but gre. Since I can't set that in SuSEfirewall2 I tried to open up the complete network by using: 10.0.0.0/8 This didn't help, either. Connecting the Win2K machine directly to the ISDN router works so there seems to be no problem with its configuration. Is it possible to configure VPN over SuSEfirewall2 at all? If yes, what am I doing wrong? Best regards, Rainer