Hi, may somebody clarify, pls: can pf do `nat before vpn' to make it is possible for LAN to access networks behind the Cisco ipsec over single ipsec tunnel ip? i talk about RELENG_8 -- Zeus V. Panchenko JID:zeus at gnu.org.ua GMT+2 (EET)