Hi,

I have the same problem described here:

http://openbsd-archive.7691.n7.nabble.com/pfsync-over-ipsec-is-broken-td257496.html#a257681

My system is 5.7 i386

I have keep state (no-sync) on all local terminated traffic (including
ipsec udp/esp) and set skip on enc in pf.conf.

I can see only outgoing PFSync traffic (no incoming) with increasing
replayed packets received on both firewalls.

netstat -p esp -s | grep replay
        304 possibly replayed packets received

Does anyone have working PFSync over IPsec Setup?

Lukasz

Reply via email to