I would hazard a guess that your servers (AD etc) do not have a static route to your ISA server?
If your ISA server passes traffic to your servers, they have to have a route which tells them to reply via your ISA server rather than the default gateway. OR you have to specify a route on your default gateway pointing all your VPN traffic back to the ISA server.
This is easy as long as you have configured your VPN IP address range on a different octet to your normal LAN...for example.
If you LAN is 10.1.1.0
Your VPN is 10.1.2.0
Your VPN Server is 10.1.1.100
Add a static route which points all traffic to 10.1.2.0 to 10.1.1.100.
That will most likely solve your problem assuming your ISA rules are all OK.
Thanks,
Mike Firth
Michael Firth
Network Infrastructure Officer
~If it's not broke, break it and LEARN~