On Tuesday 21 January 2003 06:08 am, Pekka Nikander wrote: > > then the IPsec code *requires* than any received packet > that has a source address within 192.168.2.0/24 was > indeed protected by the specified tunnel, and if it wasn't, > it drops the packet.
That's good news. I'll feel better about relaxing my rules a bit until I can figure out why I'm seeing different behavior than Crist and what is described in the ipfilter documentation (http://coombs.anu.edu.au/~avalon/ipfil-flow.html - note the final bullet item). mike To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-net" in the body of the message