Basically we are looking to create multiple tunnels from a Watchguard to Pix,Sonicwalls and Watchguards. We want to give each tunnel a 172.x.0.0 local address on the Pix side and we are coming from a 172.20.0.0. So basically we want whatever their IP scheme is to be replaced with the 172.x.0.0 subnet. The Watchguard and Sonicwall have this 1 to 1 NAT capability built in, but the Pix is another animal when it comes to this function.