Re: demystify enc interface

2006-11-24 Thread Markus Friedl
On Thu, Nov 23, 2006 at 02:47:14PM +0100, Camiel Dobbelaar wrote: I think this tells me that I can see unencrypted/unencapsulated traffic on enc0. yes. However, with tcpdump I see this: 14:09:27.894326 (authentic,confidential): SPI 0x728aafc9: 86.90.xx.xx 62.58.xx.xx: 192.168.2.3.1264

demystify enc interface

2006-11-23 Thread Camiel Dobbelaar
I'm trying to figure out how the enc interface works, and especially how to filter it using pf. This is what enc(4) says: The enc interface allows an administrator to see outgoing packets before they have been processed by ipsec(4), or incoming packets after they have been