L2TP VPN and network...

Hi folks,

Looking for a little help here - pretty sure its possible, but have been going round in circles.

VRZ Fios (with TV): Ethernet ONT to GS3100. Default router for the network

Attached to the GS3100 is a CRS_125 and a HEX.

CRS not providing any firewall.

Looking to open an ip on the GS3100 to DMZ, connecting to a HEX, with the HEX doing firewall and L2TP/IPSec. Device gets IP from IPSEC pool.

I can get a stable VPN connection, but then from the hex, need to be able to (route?) maybe from the VPN address back to the CRS. the CRS has the same network addressing as the GS3100.