>Hi all, >i have recently discovered on the list that more people is suffering the >nat problem with ipsec vpn tunnels on 2.6.x kernels, does anyone know if >its fixed on 2.6.8.1 ?? >The unique way i found to bypass the nat problem is using a proxy server >(squid), not the best solution but for now im able to surf the web .-) Hi all Sorry for my ignorance. But why would nat a vpn tunnel be a problem. Are there certain requirement for creating tunnel. Can the vpn server \ client be on the same box as the iptables gateway\router\firewall. If I remember from Anthony Stone (who seems to be missing in action, anyone know why) correctly, its best to not have any services running on fw. just something I was wondering. Kind Regards Brent Clark.