Hi Michael, Michael Richardson wrote: > > The degenerate case is a client connecting to a security-gateway/firewall > of a small organization. It should get the same inner-address as when it is > plugged into the organization LAN. In my experience, this leads to routing issues that are most easily resolved by ensuring that remote access client addresses are *never* assigned internally. Scott