I have a c2951isr at a main site and a branch site that has a c1900isr. they are linked via a site ipsec vpn. the main t.s. is behind the 2951. When nodes behind the 1900 try to rdc to the t.s. they timeout and cannot link. The external address to the t.s., outside of the vpn, works fine. They have a dns entry for the terminal server that is resolved to the internal ip address of the t.s. server and would like to reach t.s internally if can. it appears the 2951 is blocking t.s. traffic through the vpn tunnel only. should there be a special acl entry for the 2951. the basic pat/port forward is already done and working fine.