19.01.2020 14:12, Victor Sudakov wrote: > So this is most probably the artifact of if_enc. What is then the > correct way to capture data with it? This is documented behaviour of enc(4), see its manual page for description of sysctl net.enc.{in|out}.ipsec_bpf_mask