@alzhao : Can you maybe give me a hint on how this should look like … I use at the momen the policy for the client to ensure that just some devices use vpn … how would I have to adapt to ensure that I can use my regulär ISP-IP to make in inbound-VPN-connection? Thanks!