See inline
> The AD domain is the root forest.
> The NT domain has a two way trust to it.
And the users are from the NT domain? Remember NT4 relies on WINS for name
resolution.
> All DNS seems to work.
The Fact they are working doesn't mean that are correctly configured in the
clients, but since you mentioned NT4 and separated forests check WINS.
> RRAS server has an internal DMZ ip which is NATd for external IP.
> I'm using whatever protocol the default is and firewall is not blocking
> any traffic.
Not all FW/Hardware support Generic Route Encapsulation (GRE-Protocol 47,
NOT PORT 47, different things) which is needed for that.
http://support.microsoft.com/kb/241251
http://poptop.sourceforge.net/dox/gr...vailable.phtml
But once again check at Network News Groups for these questions, they can
provide you with better help there.
--
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE, MVP Directory Services