Here is something concrete: | cutomer1 LAN | ipsectun1 VLAN1 |_192.168.1/24_|============| STRONGSWAN |----------|_customer1_hosted_| | | | VPN | | | | 192.168.1/24 |============|__GATEWAY___|----------|_customer2_hosted_| |_cutomer2_LAN_| ipsectun2 VLAN2 Should be better... hopefully.