Is there a way to do this when a user is not VPN block all network access? I was looking and saw that there are inside and outside network options for defining rules. However I'm not sure what defines inside or outside network. If it is just communication with the management station without VPN then this will not accomplish what we want. What is a rule set where we can force VPN, and allow no other traffic unless VPN. I was thinking along the lines of getting an office mode IP then traffic opens, or if the client knows the user isn't VPN then deny all