Can router 3600 be used for VPN LAN-LAN Tunneling. The headquarter has 2500 router with Full T1 to ISP. 2500 connects to PIX firewall 510. PIX 510 connects to Internal router 3600. The 3600 connects to branches via FrameRelay. We might replace Frame Relay with static LAN-to-LANVPN. At the branches can 3620 routers be terminated to DSL circuit from the ISP. At the headquarter end I could terminate VPN either at the Internet 2500 router or preferreably at PIX. I would assume PIX would be the better choice.