[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: pf does not pass esp?



On Wed, 20 Mar 2002 14:42:37 -0800
Jason Ish <jason@codemonkey.net> hit the keyboard and punched:

> On Wed, Mar 20, 2002 at 11:21:34PM +0100, Rickard Borgmäster wrote:
> > I've read it here, several times. PF on -stables cannot pass esp
> > packets, while -current can.
> 
> PF will pass ESP, it just won't NAT ESP.  You need -current if you want
> ESP traffic to be NAT'd.

Hmm, okay.

Does this mean, that I cannot use ESP on a machine located behind the
OpenBSD PF firewall?

-- 

Rickard

                                               .--.        .--.
.----------------------------------------.     |  |        |  | .-.
|           Rickard Borgmäster           |     |  |        |  |/  /
|             doktorn@sub.nu             |   .-^  |  .--.  |     <
|         http://doktorn.sub.nu/         |  (  o  | ( () ) |  |\  \
`----------------------------------------'  `-----'  `--'  `--' `--'