Re: L2TP VPN / pf

2014-02-27 Thread Paul B. Henson
> From: YASUOKA Masahiko > Sent: Thursday, February 27, 2014 5:44 PM > >> In L2TP/IPsec, "transport mode" IPsec is used instead of tunnel mode. > >> This means enc(4) is not used. And de-capsulated L2TP packets are > >> received on the same interface which receives IPsec packet. > > > > Hmm, that'

Re: L2TP VPN / pf

2014-02-27 Thread YASUOKA Masahiko
On Thu, 27 Feb 2014 13:51:10 -0800 "Paul B. Henson" wrote: >> From: YASUOKA Masahiko >> Sent: Wednesday, February 26, 2014 8:46 PM >> sysctl net.pipex.enable=1 > > Hmm, yeah, that... I had updated my /etc/sysctl.conf with that change, but > the system had not been rebooted since I did that; and

Re: L2TP VPN / pf

2014-02-27 Thread Paul B. Henson
> From: YASUOKA Masahiko > Sent: Wednesday, February 26, 2014 8:46 PM > "set skip on pppx0" needs to be improved because npppd may use pppx1, > pppx2 ... Once I've got things working, I'm probably going to want to have more explicit rules rather than skipping; if I understand correctly I can just

Re: L2TP VPN / pf

2014-02-26 Thread YASUOKA Masahiko
Hi, On Wed, 26 Feb 2014 16:32:34 -0800 "Paul B. Henson" wrote: > I currently have the following in pf.conf: > > - > pass quick proto { esp, ah } from any to any > pass in quick on em1 proto udp from any to 96.251.22.154 port {500, 4500, > 1701} keep state > set skip on enc0 > set skip on ppp

L2TP VPN / pf

2014-02-26 Thread Paul B. Henson
I'm trying to get a L2TP VPN working using npppd; I think I'm most of the way there but packets just aren't quite flowing. I'm not sure why, but I think I might be missing something or misunderstanding something with pf. I've got ipsec=YES and isakmpd_flags="-K" in rc.conf.local, and /etc/ipsec.c