... ok, I've been struggling with this exact issue for the last month or so ... I guess I wasn't expecting to need a _second_ nat rule to do the reverse. I do have one final question though - which network block needs to be on my local end of the IPSec policy? using the example CIDRs here, would I w...