hi all.. managed to sort it.. new it would be something simple.
turns out it wasnt authentication.
found a of articles on another forum.
the kb article is
http://www.securitywithpassion.com.au/index.php/component/option,com_moofaq/Itemid,143/id,3/view,categories/the section is vpn support and the two article of interest are
How to Authenticate OpenVPN against Active Directory and Intranet behind Endian an OpenVPN
it was the Intranet behind Endian an OpenVPN that gave me inspiration, because it was the simplest..
all i had to do was add the ip/subnet of each lan... local and remote to the "bypass transparent proxy to" section of the http proxy screen. had to do this on both endians controlling the vpn.
simples.. hope that makes sense and i certainly hope this helps someone