[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Wed Aug 5 14:35:41 UTC 2020


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474

--- Comment #11 from Andrey V. Elsukov <ae at FreeBSD.org> ---
(In reply to Eugene Grosbein from comment #10)

I have very basic knowledge about PF's internals, but I don't think the problem
is with if_ipsec, it does nothing special after decryption, PF will see packet
as decrypted and received on the if_ipsec interface, and I don't see how it can
fail to handle such packets.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-net mailing list