> Any way to do SNAT or another way to do what I described using 2.2.x? You could try something like : ip route add dev ipsec0 src ^^^^^^^^^^^^^^^ To enforce specific source-address selection. Jerome Petazzoni <skaya at enix dot org> -- 'I'll tell you this!' shouted Rincewind. 'I'd rather trust me than history! Oh, shit, did I just say that?' (Interesting Times)