$OpenBSD: README,v 1.3 2001/06/27 03:31:44 angelos Exp $ Currently, you have to manually configure any IPsec interfaces and do the association betweent these and the physical ones. This is done like this in FreeS/WAN: ipsec tncfg --attach --virtual ipsec0 --physical eth0 ifconfig ipsec0 A.B.C.D netmask E.F.G.H Then there is one special configuration option in the IPsec-connection sections for Phase 2 of the configuration file, named Next-hop, which should be set to the next hop's IP address along the way to the peer: Next-hop= I.J.K.L This is specific to the way FreeS/WAN works.