Re: rdomains, isakmpd, keep state (if-bound)

2016-05-20 Thread utob
i'd really appreciate any help on this topic to understand what's going on. from my understanding packets received on enc0 create the state, and after some rdomain handling via pf return traffic should also leave on enc0, so the state matches. i can see via tcpdump packets on enc0 -> rdomain 15 -

rdomains, isakmpd, keep state (if-bound)

2016-05-18 Thread utob
hi, i'm using a carp+vlan+trunk setup and isakmpd. after migrating to rdomains, i've planned to have $ext_if and isakmpd+enc0 in different rdomains, but that didn't work out, as nothing would listen on $ext_if:500 then. the main thing is, that communication via enc0 is only possible if i drop the