[Bug 273198] [14.0 CURRENT] PF recognizes encrypted IPSec traffic as coming from WAN. | NAT with IPsec Phase 2 Networks

[email protected]
Newsgroups gmane.os.freebsd.devel.pf4freebsd
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=273198

--- Comment #5 from Igor Ostapenko <[email protected]> ---
I've got port forwarding working with "rdr on enc0" pf rule using the
"pf_if_enc.diff" patch and the following settings:

sysctl net.inet.ipsec.filtertunnel=0
sysctl net.enc.in.ipsec_filter_mask=2
sysctl net.enc.out.ipsec_filter_mask=1

If you still have interest in the mentioned setup then it will be appreciated
to hear results of your testing.

FYI: the patch was committed to 15-CURRENT.

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.