Additional hardware for VPN
I am in discussions with my ISP regarding a VPN solution between my company and a few vendors around the country. My ISP tells me that I also will be needing a VSU (black box) that is configured by the ISP and will will need to be installed in front of the firewall and also installed at each vendor.
This VSU will pass IPSEC traffic between the boxes. The IPSEC traffic will be de-encrypted by the black box before entering your network. This is good because we use NAT services which cannot work with IPSEC.