Currently using ACS for Win pointing to external Windows NT domain database. PIX is setup to authenticate VPN clients and authenticate outbound http access to this same ACS. Working ok but while I want all inside users to be able to browse the Internet once authenticated, there is only a small subset of users I want to be able to connect through VPN clients. How can I provide authorization functionality to control who can connect with a VPN client?