well, if the CA is running, it is running. if the router is rebooting, then no traffic will get through until it is back up. for the cert, well, you gotta get that from the CA. i think (and i am just thinking here...) that if you can tunnel in via PPTP, that you should be able to request a computer certificate over the VPN. first off, the computer must have an account in AD. are your VPN client's in AD? do the user accounts you are using for the VPN have the "dial-in" "Remote Access Permissions" set to Allow? (it is deny by default - unless upgraded from NT 4.0) and "no callback" for the callback.
are you connecting to RRAS ?
scottie