>As I said earlier, packets which route through ipfw/natd get unencrypted and >make it to the remote subnet just fine. > >Looking at 'ipfw -a l' it seems that the ESP packets are being received >_after_ being diverted to natd, but just >not sent to the socket:
I'm no IPsec expert (still something I need to look into) but something that springs to mind is to allow the packet before the natd divert. I couldn't say why this would work (since natd shouldn't touch the packet, and you say other packets go through fine), but it's just a hunch =) DocWilco To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-net" in the body of the message