19.01.2020 14:12, Victor Sudakov wrote:
> So this is most probably the artifact of if_enc. What is then the
> correct way to capture data with it?
This is documented behaviour of enc(4), see its manual page for description
of sysctl net.enc.{in|out}.ipsec_bpf_mask