Yes, it's going through ISA. The firewall rules are wide open.
The problem is with name-resolution. On dial-up (and on a Mac, and presumably on *nix) everything works fine ... but with XP on broadband (not PPPoE) names don't resolve correctly.
Interestingly, a tracert while connected to the VPN to an internal machine goes into the internal network and then back outside. Almost like the internal network doesn't know what to do with it coming from the VPN.
I agree that Microsoft's VPN client is crappy ... but like I said I don't have a choice in the matter.
|