When a remote Win9X client tries to log into a domain without a tunnel, it times out (of course). Then, if you establish a client VPN connection, you get layer 3 connectivity and can browse by IP address or use LMhosts file entries. If you try to log off and log into the domain, you lose your tunnel. So can someone please point me to the document that explains how you establish a tunnel and then Log into the domain? With Win2K the Tunnel comes up before the actual client-->Domain authentication happens. How do you do it in Win9X? Also, I tried configuring WINS and DNS servers for my groups, but but they only recieve the address of the DNS server, not the WINS server. Worthy of note: I am using a Win2K server, not NT. I am running WINS and DNS on it. I am only able to browse by IP address at this point. Some concise documentation explaining the underlying architecture would be fantastic.