HI!
What you want is not so simple.
One option you have to remove AD (using DCPROMO), and then join the NT4 domain as a MEMBER SERVER, WITHOUT installing AD.
This is for my opinion the best way for you, until you wish to upgrade the domain to W2K AD.
For the VPN stuff, it can be implemented in the FireWall and not on the internal server.
And anyway I don't think that Active Directory is required for implementing VPN in 2000, it just gives you more option if you're in native mode, which is not suitable for your current network.
If you try to install AD to the same NT4 domain using DCPROMO, I think you'll have problems, because this means that you are trying to upgrade the domain to W2K and AD , and for this to be done you should have an NT4 PDC upgraded to 2000.
So I think this won't work and will give you some hard time.
There are other options but can be more complex and dificult to implement.
Bye
Yizhar
Yizhar Hurwitz