Yo It looks like I fugured out part of the Problem.
The different 'public' local networks are connected to an IPSEC Tunnel on the WAN side. So there is an 'encrypt' policy for those three networks with destination 0.0.0.0/0 Now it looks like RouterOS tryes to encrypt such packets even if the don't leave through the tunnel but are from one local network to the other. Does anyone know a way how to allow local to local traffic if an IPSEC tunnel with destination 0.0.0.0/0 exists? Benoit Panizzon -- I m p r o W a r e A G - ______________________________________________________ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 Pratteln Fax +41 61 826 93 02 Schweiz Web http://www.imp.ch ______________________________________________________ _______________________________________________ Mikrotik mailing list [email protected] http://www.butchevans.com/mailman/listinfo/mikrotik Visit http://blog.butchevans.com/ for tutorials related to Mikrotik RouterOS

