I have to masquerade the pakets out of the tunnel, because this packets should be routed into the subnet and they have to send back to the vpn-gate. At the moment, the packet arrives with his external IP at the client, and is send back over his standard-gate. Can anybody help me? THX Ben