John, thanks for the information about route2.  I am running a testbed where all connections for the testbed machines (a mix of XP, RedHat ES, and FC2 boxes) are covered by OpenSWAN IPSec (using PSK for the moment).  I added one FC2 machine to the network that is a gateway to the Internet.  I had to change the connectivity such that connections from my machines out to the Internet are in the clear while on the testbed.  I've been trying to find a way to use IPSec to cover the connection from the originating machine to the testbed NIC, then forward the packets on out to the internet:
                |      (IPSec coverage)         |<-  |
    Workstation |-------------------------------|     Gateway     |---------- Internet
  (192.168.10.x)|                               |> |
The workstations are XP boxes.  They are set to IPSec cover all traffic on the network except for any destined for the Internet.  I'd appreciate any pointers.
Where is your rightsubnet defined for the connection? You will also want
to make sure that your IDs match exactly.  There is a slightly dated
slide show which includes setting up NAT traversal in the training
section on http://iscs.sourceforge.net There's even a section on using
iproute2 so that the network VPN connection can be used to speak to the
gateway through the private interface eliminating the need for extra
connection definitions.

By the way, does your gateway allow the traffic destined for the gateway
bound traffic on the INPUT chain? It will use that rather than the
FORWARD chain for traffic destined for the gateway.

Good luck - John

