Just out of my own curriosity have you gave the thought of using deadicated or virtual circuits for the VPN implimentation? Like Frame Relay or ATM? Are you passing off the connections to a secondairy network access server? Or how do you plan on rolling this out, configuration wise?
user will connect vpn using isp leased line. vpn server in dmz. application server is in inside network. no planing for atm / frame relay.