https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474
--- Comment #30 from j...@netgate.com --- You can have both route-based and policy-based IPsec active at once but you cannot filter both at once in the expected manner. It is not limited to NAT rules, it affects both NAT and firewall rules in pf (and presumably others) which attempt to filter directly on if_ipsec interfaces while filtering is also active on the enc interface. -- You are receiving this mail because: You are the assignee for the bug. _______________________________________________ freebsd-net@freebsd.org mailing list https://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"