Thank you for your reply. I admit I am misunderstanding what's going on.
I'll try to explain this a little better since I think my 1st port was too long and not easy to understand.
(Domain A 192.168.1.1) Shared to & VPN Via IPSEC (Domain B 192.168.2.1)
ext Ip 70.25.. ext ip 50.54..
Citrix & Mail on Domain A
Domain B can't reach Domain A if using the ext IP but can speak using internal IP 192.168.1**
Domain A was only to contact itself using the ext Ip once I selected. "Disables the automatic creation of additional NAT 1:1 mappings for access to 1:1 mappings of your external IP addresses from within your internal networks. Note: Reflection for 1:1 NAT might not fully work in certain complex routing scenarios."
This did not work for domain B
"Reflection does not work for IPsec hosts, in most all configurations the public network isn't even sent over the VPN so it's not needed, unless you're routing everything over the VPN"
To my knowledge not everything is routed over the VPN, when users browse they are browsing through their local ISP, When I run speed tests or ip lookup in Domain B their IP is displayed (I'm assuming this would let me know)
Sounds like you may have to have split DNS in that setup
Can you explain this a little further this may be the case but if you can provide me with a little direction I'll understand what to change.
Thank You for the advice.
I think you alread understand my issue but I wanted to make it a little clearer.