NW6.5sp2 w/ BM3.8sp2a

I am setting up a new BM server and want to use the C2S VPN, ACLs w/ proxy services and packet filters. Currently, I have the HTTP proxy and VPN both up and running. Default filters are enabled and the server is configured as a "Router" in INETCFG. The default filters don't seem to be working with the server set as a "Router". However, when I change this to "End Node", my VPN clients can not access anything thru the BM VPN.

Anyone have any ideas?

Thanks.
Richie Tenhet