Hello, Michael Gale wrote :
Am I correct that mutliple GRE (proto 47) tunnels would be a problem when the clients have the same IP address ?
Yes, unless the NAT in "firewall A" has PPTP support.
We are running the standard kernel 2.6.9-42.0.3.EL.
On "firewall A" ? If so, can't you use a more recent kernel ? PPTP conntrack and NAT support, formerly in the patch-o-matic-ng, was added in the mainline kernel in version 2.6.14.