You could put another pfsense on private IP space at HQ that knows how to forward the packets back out.
So the routing decision would be made after it's traversed the tunnel. Should be simple enough. --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]