Hi Philippe, > My question: what is the best/recommended way of escaping my trafic which needs protection from masquerading? Use the policy module, see [1]. Regards, Tobias [1] https://wiki.strongswan.org/projects/strongswan/wiki/ForwardingAndSplitTunneling#General-NAT-problems