Deploying several VPN 3002 Hardware clients in network extension mode logging onto vpn3030 with userid/password and IPSec group. Desire to create a filter and rule to apply to each vpn 3002 userid to allow only a prefined IP address ( dsl static address ) to be used to logon. This would prevent the vpn3002 from being stolen and re-connected to the crooks home internet line to access the victims HQ core network.