Oh I just wanted to encrypt 5.5.5.5 <---> 1.2.3.32/28 and I thought it wasn't necessary to specify 5.5.5.5 in leftsubnet since it was already in the leftip. It does work now, thanks for the help. Cheers, Niccolò