Hi Greg, thanks for your great post. Does the IP address assigned to the LTM have to be publicly routable, or can it be a private IP that is behind a NAT device? I also read your previous post on policy-based IPsec VPNs using the LTM to connect to Azure, but I am limited in that my LTM is behind a NAT (and currently running version 11.6 for that matter, so I believe I'm limited to policy-based VPN until I upgrade to 12.x). Is there a way to use NAT Traversal and configure a LTM that is behind a NAT to create an IPsec VPN with Azure?