Re: IPv6 IPsec transport pf

2017-05-11 Thread Mike Belopuhov
On Mon, May 08, 2017 at 20:22 +0200, Alexander Bluhm wrote: > Hi, > > IPv6 IPsec transport mode does not work if pf is enabled. The > problem is that the decrypted packets in the input path are not > checked with pf(4). So if you have stateful filtering on enc0 (the > default) direction aware

IPv6 IPsec transport pf

2017-05-08 Thread Alexander Bluhm
Hi, IPv6 IPsec transport mode does not work if pf is enabled. The problem is that the decrypted packets in the input path are not checked with pf(4). So if you have stateful filtering on enc0 (the default) direction aware protocols like ping or TCP do not pass. Only the output packets are