Thank you for reply Mary.. actually my SME Server is only act as AD and im using other firewall OS and now i don't know how can make this setup?

Modem <- -> Firewall <--> AD (SME Server)
first of all, SME is a DC in NT styloe, so not an AD DC

that said, I managed to login to SME's domain via vpn
you need to configure your firewall to forward port tcp 1723 ans protocol 47 GRE to SME (sometimes it is called vpn passthrough or similar)
then, you need to setup a vpn on your clients in the branch office..
at login time (I'm referring to windows XP) you should have the option to use a remote connection
anyway, google will tell you more
ah.. time to upgrade to SME8 final
