Does anyone know why we don't use redirection to a new gateway for ipip encapsulation? It's simple, useful and I don't understand why we don't do it. I've put together a couple of simple scripts to test my ideas and they work like this.... If an incoming ipip packet is going to turn around and become an outgoing ipip packet the gateway that sent the ipip packet is sent an information packet containing the new gateway and host addresses. The gateway receiving this information packet adds a route that expires in 5 minutes. The gateway that sends the information packet doesn't send another information packet for this gateway/host pair for 5 minutes. What do ya think? Bob