I'm having a similar problem and am not very experienced yet with iptables. > Make sure you are forwarding (both ways :-) protocol 50 (ESP), protocol 51 > (AH) and UDP sport 500 / dport 500 (IKE). Could you show me the best way to write this in iptables syntax? George