I have an existing cisco ASA 5515 peering statically with our ISP and a new Cisco 4431 that we want to use as a VPN concentrator for our remote offices. The ISR is to provide Ipsec\GRE tunnels to our remote sites which have ISR's peering with their ISP's. I am not sure where the ISR should live in relation to the ASA (DMZ \ Separate Inside interface \ Infront of the ASA etc.) I have attached a diagram that illustrates how the design looks any suggestions would be appreciated.