I have a fresh 10.5.3 advanced server setup and I ran the NAT wizard to get my basic gateway up and running. Everything with the gateway works great, VPN works internally, VPN does not work from external address. First tested with firewall turned off, and VPN works as expected. I looked at the firewall rules using server admin settings/services screen and it looks like the wizard correctly checked the VPN L2TP (port 1701) and VPN ISAKMP/IKE (port 500) boxes. However, when I connect from my client I don't get any acknowledgment in the logs, as I do when the firewall is turned off. Before I go hacking around to make things work, I am wondering why these settings don't work? It seems the wizard set everything up correctly, and it is not obvious why this configuration does not work out-of-the-box. Thanks for any insight.