I got everything to work based on the Undeadly article and the information in this thread.
A few remarks: - when connecting with an iPhone 3des in ipsec.conf should be replaced by aes - uncomment the line with net.pipex.enable=1 in sysctl.conf - add npppd_flags="" to rc.conf.local so npppd is started automatically at system boot And one question: Do we really need to allow ah in pf.conf? I have it working with just esp. Daniel ==== Original message from mxb at 22-7-2014 13:15 > As been the original author of undeadly.org article I can state that info in > is stil partially valid, except npppd.conf part.

