On Tue, 29 Aug 2006, Andy Gay wrote: > Seems you need pfs=yes, AFAIK that's what "pfs group 2" means in the > Cisco. Luckilly, if openswan detects PFS, it will use it despite the pfs=no setting :) Paul -- Building and integrating Virtual Private Networks with Openswan: http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155