On Thu, May 18, 2006 at 10:24:50AM +0000, peters at exemplar-associates.com wrote: > It is a firewall issue. I have ports 500, 4500 and 445 open > and I thought that would be enough. Oddly Firestarted doesn't > log any rejections. You need: - UDP 500 - UDP 4500 for NAT'ed clients - ESP (= IP protocol 50) for non-NAT'ed clients