The end-to-edge model of DirectAccess has the DirectAccess client establish an IPSec tunnel to the DirectAccess server. The DirectAccess server then forwards unprotected traffic to the intranet ...