Hello, Sorry I didn't get back to this sooner, but I got very busy. Have you solved this issue yet? If not, here are a few suggestions to try: In your /etc/ipsec.conf - Change your config setup to interfaces="ipsec0=eth0" Change the following items in your config cisco to left=213.131.75.130 leftsubnet=10.0.0.0/24 leftnexthop=213.131.75.129 right=213.131.60.250 rightsubnet=0.0.0.0/0 # Any subnet connecting to your Cisco 2600 - you can narrow it down if desired rightsubnet=(IP address of WAN side of your Cisco 805 - should be something like 213.131.60.???) Note that in the config file you included in your previous posts, by specifying your left side as 10.0.0.16, you are outside the endpoints of your tunnel (i.e. your tunnel should be left side ( eth0 (213.131.75.130) to LAN side of your Cisco 805 (213.131.75.129) ) to right side (WAN side of your Cisco 805 (213.131.60.???) to Cisco 2600 (312.131.60.250) ). Hope this helps. For more info (a little old, but still good info) see http://www.sans.org/rr/papers/index.php?id=753 Sam -- redhat-list mailing list unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe https://www.redhat.com/mailman/listinfo/redhat-list