conn vpn left=1.2.3.4 leftsubnet=192.168.0.0/24 right=5.6.7.8 rightsubnet=10.0.0.0/8 [...] then add the required iptables NAT rules that avoids bad interaction with existing rules or the IPsec ...