I'm curious to know the following:

If I have an OpenBSD machine running isakmpd that is acting as 
a gateway for an internal network (NAT), are IPSec connections
from a client on the inside network (10/8 address space) nat'ed
as packets go through the machine to the outside world?

I ask because I've seen some packets going out (traceroutes) with
destination host unreachables, and it appears this is due to 
an egress filter on the ISP's head-end blocking 10/8 addresses.

Thanks for any info.