>>Is it possible to configure the NetBSD boxes as firewalls while they >>are doing the tunneling? > not with 1.5. http://www.netbsd.org/Documentation/network/ipsec/ > has some caveat documented in it. oops, you are on netbsd-current. you can do this. itojun