A real life solution to the mobile VPN problem will be presented. It uses OpenBSD on a laptop with a IPsec tunnel to a gateway. The real benefit to the audience is that potential security vulnerabilities will be discussed (e.g., sending IKE ID in the clear, allowing udp/500 to the gateway from all IP addresses, the use of Aggressive vs. ID Prot mode in Phase 1). In addition, potential solutions to those vulnerabilities will be presented.