If your firewall is capable of being a VPN tunnel endpoint then I think the VPN is more secure. As for speed, if either end is a dial up forget it. If both are cable/dsl or better you'll be just fine. What helps is to have a VPN tunnel to a Terminal Services box on the inside so that the processing takes place there and only the IO goes back and forwards.... Then you might as well be sta at the TS box itself.