Hi all,
Probably fed up with me now

but dont let that put you off

Ive boiled it down to either using the same domain name on both my extranet and internal network, or separating the extranet from the internal network but implementing ADFS for user authentication with sharepoint.
(For those that dont know what im on about see my previous posts!)
http://www.techexams.net/forums/off-topic/44377-help-network-design-sharepoint.html
its much easier to keep it under the same domain name and allow authentication, but implementing ADFS seems more secure, but is it worth the extra effort? any ideas? what about security?
thanks all!