OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: pf filtering based on SA?

From: Henning Brauer (lists-openbsdbsws.de)
Date: Tue Nov 02 2004 - 06:04:41 CST


* yary hluchan <not.comgmail.com> [2004-11-02 11:55]:
> I'm setting up a VPN, using isakmpd on my opensbd 3.5 gateway. Is
> there any way to have pf filter based on which SA the packets entered
> the local network?

no. we discussed that multiple times, and it comes up about twice per
year, and at the end of a long discussion it is always pretty obvious
that it doesn't make sense.