I stumbled across http://www.linuxhomenetworking.com/linux-adv/vpn-linux.htm today, which states that "NAT breaks VPNs". Is this just an over-simplifying statement that really means "if you're reading this, then don't even try setting up a NAT-traversing VPN"? This is exactly what I'm planning to do; I've got my mind set on having the two VPN endpoints inside two NATed networks, both managed by respective dedicated linux boxes running only netfilter. If that is indeed possible (and doable for a first timer), could anyone provide some relevant pointers to documentation? Cheers -A