This may have been touched upon, but I just wanted a clarification. Can you establish an IPsec (triple-DES) tunnel when using one-to-one NAT? I know NAT overload scheme disrupts the header information, and prohibits IPsec tunnels. VPN is sponsored by SecurityFocus.COM