forgot to mention, fastrack already disable.Not by accident still have fasttraking active?I am using default configuration, bridge ether2 to ether5 as LAN, except WAN is pppoe client, add LAN subnet to ipsec policy as suggested by Sindy, but unable to browse anything on internet.