>- is it possible to establish an esp-tunnel with a NAT in-between the 2 > sides of the esp-tunnel ? no. it's impossible. there are internet drafts available for it, but there's no plan for us to support it (it's too wacky and success/ failure depends on the behavior of the NAT product you are using) itojun