reply to tweaker_ui
Really, you cant change the port number or come in on a different port and then translate it to port 500 for a specific lanIP???
In theory you could for most services. In reality not for IPSec. Also USG doesn't support that. You can either have IPSec terminated on USG or pass-through. Not both at a same time on one interface.