I am doing testing from home at present with an ap and a 620 using a site to site VPN back to the office, just as Colin has suggested - in effect I have created a mini branch office. No problems at all for me, this is a working configuration - I even forward dhcp requests to cppm for profiling. Cool thing here is stuff like Mac caching detail and captive portal authentication is held centrally so I get the same experience when I walk into the office, so the experience is it 'just works'.