> Any way to do SNAT or another way to do what I described using 2.2.x? You could try something like : ip route add 192.168.1.0/24 dev ipsec0 src 192.168.1.1 ^^^^^^^^^^^^^^^ To enforce specific source-address selection. Jerome Petazzoni <skaya at enix dot org> -- 'I'll tell you this!' shouted Rincewind. 'I'd rather trust me than history! Oh, shit, did I just say that?' (Interesting Times)