@saper :) Yep! I've gotten that far. For tunnel mode I'm currently still failing to understand how traffic selectors, private subnets interact and when do you need a virtual ip.