Re: pf rdr statement & ipsec processing interaction

2007-08-18 Thread Eric Masson
Eric Masson <[EMAIL PROTECTED]> writes: Hello, > So outgoing l2tp packets should be esp transformed, right ? I've been able to reproduce the problem on a -current box (sources from yesterday), should I file a PR ? Regards Éric Masson -- C'est vrai peut t'on renconter quelqu'un sur internet?

Re: pf rdr statement & ipsec processing interaction

2007-08-14 Thread Eric Masson
"Bjoern A. Zeeb" <[EMAIL PROTECTED]> writes: > ifconfig enc0 | grep UP > > if not, ifconfig enc0 up Ok, this is better as mpd4 receives l2tp packets, thanks :) [EMAIL PROTECTED]:~> sudo /usr/local/sbin/mpd4 Multi-link PPP daemon for FreeBSD process 1586 started, version 4.2.2 ([EMAIL PROTECTED]

Re: pf rdr statement & ipsec processing interaction

2007-08-14 Thread Bjoern A. Zeeb
On Tue, 14 Aug 2007, Eric Masson wrote: "Bjoern A. Zeeb" <[EMAIL PROTECTED]> writes: Hello Bjoern & all, this is expected behavior. You want to read about the IPSEC_FILTERTUNNEL (fka. IPSEC_FILTERGIF) kernel option and enc(4). I've compiled a new kernel with IPSEC_FILTERGIF, tcpdump now can

Re: pf rdr statement & ipsec processing interaction

2007-08-14 Thread Eric Masson
"Bjoern A. Zeeb" <[EMAIL PROTECTED]> writes: Hello Bjoern & all, > this is expected behavior. You want to read about the > IPSEC_FILTERTUNNEL (fka. IPSEC_FILTERGIF) kernel option and > enc(4). I've compiled a new kernel with IPSEC_FILTERGIF, tcpdump now can see unencrypted L2TP packets on extern

Re: pf rdr statement & ipsec processing interaction

2007-08-13 Thread Eric Masson
"Bjoern A. Zeeb" <[EMAIL PROTECTED]> writes: Hi Bjoern, > this is expected behavior. Fine, > You want to read about the IPSEC_FILTERTUNNEL (fka. IPSEC_FILTERGIF) > kernel option and enc(4). Ok, thanks for your help Regards Éric Masson -- DP>à partir de quand n'est-on plus un neuneu? est-c

Re: pf rdr statement & ipsec processing interaction

2007-08-13 Thread Bjoern A. Zeeb
On Mon, 13 Aug 2007, Eric Masson wrote: Hello, I'm trying to setup a FreeBSD 6.2 box as l2tp/ipsec server for MS workstations (FAST_IPSEC + Yvan's NAT-T patch) Thanks to mpd4, the l2tp part works fine, as the box could in fine have only a dynamic ip address, I've made mpd listen on a loopback

pf rdr statement & ipsec processing interaction

2007-08-13 Thread Eric Masson
Hello, I'm trying to setup a FreeBSD 6.2 box as l2tp/ipsec server for MS workstations (FAST_IPSEC + Yvan's NAT-T patch) Thanks to mpd4, the l2tp part works fine, as the box could in fine have only a dynamic ip address, I've made mpd listen on a loopback interface on the box and then redirected in