Our XGs mainly sit within the same network but at different branch offices connected via a IPVPN converged services network provided from out ISP. So the WAN port has a private IP address, and to use NTLM and other services, the WAN zone was disabled and a IPVPN zone used in its place. The problem I am having is that even with a IPVPN zone to LAN zone allowed rule created, the XG will stop allowing traffic from the WAN port inside the FW. I have to keep a constant ping going from a server outside the network to either the FW or a server inside the network to keep the device open. An example is that I would be unable to RDP into a server on the LAN side of the XG from my laptop on the IPVPN WAN side of the XG. Thank You for your help.