> I can see that this won't work for Racoon/Racoon, but TimeStep Permit at >the end does let me do this. Once I establish a tunnel for the inside >addresses, they will route stuff to me. they basically hardcode "SAD inserted then install SPD" kind of rule into their IKE daemon. itojun