HI Fabil, Its very difficult to explain unless you give the exact scenario.Normally you configure an access list for the VPN traffic and deny the NATing using "nat (inside) 0 access-list " command.
Try the below link. You will find all the configurations there. http://www.cisco.com/pcgi-bin/Support/PSP/psp_view.pl?p=Internetworking:IPSec&s=Implementation_and_Configuration#Samples_%26_Tips Hope this helps, regards, Silju Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=50555&t=50417 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

