On several of the boxes that I admin, starting ipsec on boot in the normal way, i.e. from rc.conf.local, doesn't work. The problem 'seems' to be that ipsec is looking for /var/run/isakmpd.pid, can't find it, and won't start. A simple solution is to start ipsec from rc.local after starting isakmpd from rc.conf.local. Not a big deal, just seems a kinda funky way to do things.
-- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security "You guys, I don't hear any noise. Are you sure you're doing it right?" -- My Life With The Thrill Kill Kult