Re: Broken IPsec + enc +pf/ipfw

2014-10-21 Thread Kyle Williams
On Tue Oct 21 11:35:15 2014, Matthew Grooms wrote: >Hey Kyle, > >Thanks for lending a hand. I tested a few myself last night but had no >luck. This morning I received an email off list that pointed to a patch >that was merged to 10 stable. It sounds promising ... > >Log: > Merge r263091: fix mb

Re: Broken IPsec + enc +pf/ipfw

2014-10-21 Thread Matthew Grooms
On 10/21/2014 11:06 AM, Kyle Williams wrote: Hello, I'm currently using 10.0, IPSEC, racoon, enc, and pf between two remote hosts without NATT. The gif tunnel is ipv4 only, host A is ipv4 only, host B is ipv4/ipv6. I use IPSEC to route traffic between jails on both hosts, with the jails using cl

Re: Broken IPsec + enc +pf/ipfw

2014-10-21 Thread Kyle Williams
Hello, I'm currently using 10.0, IPSEC, racoon, enc, and pf between two remote hosts without NATT. The gif tunnel is ipv4 only, host A is ipv4 only, host B is ipv4/ipv6. I use IPSEC to route traffic between jails on both hosts, with the jails using cloned lo1 and 10.0.0.0/8 addresses. I'm testing

Re: Broken IPsec + enc +pf/ipfw

2014-10-21 Thread Andrey V. Elsukov
On 21.10.2014 01:34, Matthew Grooms wrote: > https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=110959 Did you try the patch from last PR? It is small and should be applicable to stable/10. >>> >>> As I mentioned, it's not clear to me if the patch was intended to fix >>>