Ok, bear with me here. I've got a complicated issue, and I've got a few plans, but I want some outside input.

Here's the restrictions, areas of concern

3 physical locations
Fiber lines ran between each to another (4th) location, but nothing of ours is @ that 4th location...just a switching location

Whats definately out
Running direct fiber connections, too much per month charge (I wanted that so bad)

Goal :
our own AD domain, exchange, cut off from the network we are currently on but not necessarily on a physical aspect, I'm lookin VPN or VLAN...

I was considering running routers at each location with an 04 ISA server (firewall, router, VPN) between each section, AD server behind each, VPN tunnel running between each. OR splitting ourselves with a VLAN ::shrug:: ...i'm up for any and all ideas.