Hi Lars, > conn psk-l2tp > keyexchange=ikev1 > authby=psk > rekey=no > type=tunnel Try type=transport. The clients are most likely to propose that and 5.2.1 now checks that the proposed mode is the one that is configured. Regards, Tobias