We are having the same issue at two different client sites. We preprogrammed a Nortel 1010 (which worked here) and had it installed at the client's site. The tunnel comes up fine, but we cannot ping the 1010's mgmt IP or the client's host unless the client pings us first from the host (the routing is done by a persistant route on the host). Both clients have a simple network config (single static IP from their ISP, with WAN connection into a cable or DSL router). We configured the private interface only on the Nortel, with an inside LAN IP. I know that one client has a Zyxel Prestige modem. Don't know about the other client yet. Any ideas why we cannot ping? We are NATing the clients' local networks on the 1010's because we avoid network redundancy with other VPN tunnels that way. Ideas? More info needed?