Here is my initial setting: Router is a Wrt54g with the Sveasoft Alchimy firmware. Wlan connection is connected to a DSL modem and use PPOE. Lan router IP is 192.168.0.200 PC1 (Windows XP systems) is connected to the router on Ethernet port 1 and have IP 192.168.0.1 PC2 (Windows XP systems) is connected to the router via a wireless connection and have IP 192.168.0.2 PC3 (Windows XP systems) is connected to the router on Ethernet port 2 and have IP 192.168.0.3 At this time, 3 systems are able to ping itch other and shares located on PC2 and PC3 are accessible from PC1. I try to deploy IPSec in â€œTransport modeâ€ on the 3 computers. I create the same policies on the 3 boxes: Data integrity and encryption is required for all traffic from/to 192.168.0.0. This rule does not specify an IPsec tunnel. Pre-shared key is used for authentication. At this time, connectivity between PC1 and PC3 still working, but every connection to PC2 fails. Into the PC2 security log event, I see IKE negotiation occurs but fails. And more important, source IP is not IP of PC1 or PC3 but the router Lan IP!!!! It seems the router use NAT between Ethernet Lan and wireless Lan, even if the connected PCs are all into the same subnet, and IPsec in transport mode is not usable with NAT !!! Could you confirm me NAT is active between these two interfaces? In this case, is it possible to use a command or an alternate firmware to disable the NAT between these 2 interfaces?