header

Categories::

Projects::

SAGE
M4RI
Code Snippets
ECrypt II
iliketotallyloveit

Stuff::

Junge Linke (de)
Battrock (de)

MiniMe::

BitBucket
Flickr
Tue, 11. Oct 2005

pf.conf for IPSec

As I needed approx 4 hours to figure it out even though it’s pretty simple. When playing around with IPSec under OpenBSD (isakmpd) and your Security Association is finally established but you cannot ping around make sure you have
pass quick on enc0
in your pf.conf.

While you’re editing pf.conf you might want to add some scrubbing for your traffic as IPSec increases the MTU:
scrub on $ext_if all fragment reassemble random-id no-df max-mss 1440
You don’t really need reassemble, random-id and fragment.

posted at: 23:57 :: permanent link

Valid XHTML 1.0 Strict Valid CSS! blosxom