I had thought about forcing Kerberos to use TCP but had dismissed the idea since the problem is that the remote users cant contact the domain before they log in since they are not on the local network.
I'll make the change anyway and see if it helps. At the very least it may help authenticate better with a split tunnel so I could set the VPN to activate on logon...

Thanks, for the idea, keep them coming please.