On 05/04/2012 13:52, Sabahattin Gucukoglu wrote: > How do you propose to make end-to-end crypto of packets possible where > NATs are involved? same way as we've done for years: payload authentication/encryption only. header authentication makes no sense. Nick