Bernd Bednarz wrote:
j knight wrote:
  pass out on $dsl2 route-to ($dsl1 $gw1) from $ip1 to any
  pass out on $dsl1 route-to ($dsl2 $gw2) from $ip2 to any

Why did you remove them?

because the reply-to rule make the same for me and I don't need both of them. When I ping the router on tun1 the packets go trough tun1 with the route-to oder reply-to and thatsway I only have the one rule reply-to

I didn't mean for you to replace the reply-to rules with route-to rules, but to have both pair. The route-to rules will prevent exactly the problem you're seeing: packets leaving $if1 with a source IP of $if2 (and vice-versa of course).

Reply via email to