vpn behind nat to server

I have noticed that only one person can vpn from our network to a server
outside of our net.    It does not matter if the both clients are going
to the same place or different servers.

Vpn client -> natd/firewall -> vpn server.

I have searched mailing list archives and seems most questions are for
incoming connections, not outgoing.

I am running a nat/firewall box with the following ipnat rules:

map xl0 -> portmap tcp/udp 10000:20000
map xl0 ->

I am running quite intensive ruleset that i would like to avoid coping to
an email but let me know if you need a copy to help.

If anyone has some insight on solving this, i would appreciate the help.


