AW: [Bug 296598] pf: IPsec tunnel mode over if_wg, inner header not visible to pf

From: Krämer, Lars <lkr_at_wizard.de>
Date: Tue, 28 Jul 2026 09:09:35 UTC
Ah, my bad.
Strike the reproduction on 15.1, I think I missed these sysctls initially:
sysctl net.enc.in.ipsec_filter_mask=2
sysctl net.enc.out.ipsec_filter_mask=1

The pf_setup_pdesc machinery does seem to have fixed this, but it's only in 15.x.
14.4 still does have this, the first mtod isn't gated by any checks as far as I can tell.

Thanks,
Lars