We require the aggressive IPSEC tunnels as the 4g provider only provides a dynamic WAN ip. Phase1 comes up fine. Cisco, PFsence, Netgear, Juniper, Fortinet, Billion, Draytec, Frizbox All seem to support this feature using local and remote identities based on hostname or IP address. The issue I have ...