Assuming a common network topology consiting of a 3 legged firewall with internal network and DMZ, where would a vpn server be commonly placed? (VPN for remote users, not site-to-site)
-ON the firewall?
-behind firewall on the internal network?
-behind firewall in the DMZ?

What kind of authentication is commonly used with users?

Could/should vpn auth be integrated with internal network's DCs (W2k pdc for example (with kerberos?))

Thanx

Ammo