Javier Villavicencio wrote:
[big sad snip]

Sorry for bothering you people, the solution was to add this to /etc/sysctl.conf (or just sysctl'ing the damn thing):

net.inet.gre.allow=1  # Allow GRE packets in and out of the system.

Weird btw, and the "fact" that didn't lend me to think about this kernel variable, with that to 0 I was able to connect from computers on the LAN to the VPN, of course with the redirects 'n stuff in pf.conf. Seems that pf's code have higher priority than that kernel's stuff :+/

Salu2.

Javier Villavicencio.

Reply via email to