I'm trying to get the feel on how corporate dmz's are designes. For example, I would like to do a dmz for wireless. I will be using isa server 2004. This is what I have in mind the isa 2004 will go behind a watchguard firebox 700. Ok I'll have 3 interfaces on the box one lan wan and the other for the wireless dmz. Lets say the lan is 192.168.1.0 network the wn will be 192.68.1.2 with the gateway of the firebox 700 being listed as the wans default gateway. The wirless dmz segment will be 192.168.5.0 network. I will give out a vpn addresses that are on the 10.0.0.0 network. I'm trying to figure out do I need to add any static routes to the isa server 2004 box. I'm assuming I'll have to route the 10.0.0.0 network into the lan which is 192.168.1.0. Let me know if you guys see any problems with what I'm thinking about?