Try this: Add this rule to your nat-table. -A POSTROUTING -p 50 -j ACCEPT This allows esp not to be NAT-ted ! Succes, Alfred. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.openswan.org/pipermail/users/attachments/20050411/10b471d1/attachment.htm