I was having problems with using the SME as the VPN server, but I think it was just DUN issues on the client. Reinstalling DUN seems to have fixed it. It does pass on the domain login to the PDC as well, so everything seems to work the way we want it just by using the SME.
Is there any way to specify what IPs the SME hands out for VPN clients? As I said, we're using the NT PDC for DHCP, giving clients 10.0.100.x addresses. The SME (10.0.0.1) hands out 10.0.0.x addresses for VPN... It shouldn't cause any conflicts or anything this way, but it would be nice if I could specify a range in 10.0.100.x to use...