I am perhaps stupidly stuck at the moment! I have created a successful VPN tunnel to my OBSD firewall and want to access an FTP server on the internal LAN (or mail server for that matter). However I cannot unless I change my rules to ipf.open to test the problem. Any advice on what I am missing in my rule base to permit VPN traffic to act as if it was on the internal LAN? Thanks, Dean Carey