I think that genixia was referring to the possible routers people might have on the client side. If you go the VPN-endpoint-in-DMZ route, then it's not an issue on your side. But if your firewall supports it, you could not bother with a DMZ and just put the VPN endpoint in your normal network, which is probably more secure.

http://vpn.ebootis.de/ is a free solution that ought to work, but will take much longer to set up, and probably be a little flakier. I'm sure that there are other similar solutions out there.
_________________________
Bitt Faulk