Javier Villavicencio wrote:
[big sad snip]
Sorry for bothering you people, the solution was to add this to
/etc/sysctl.conf (or just sysctl'ing the damn thing):
net.inet.gre.allow=1 # Allow GRE packets in and out of the system.
Weird btw, and the "fact" that didn't lend me to think about this kernel
variable, with that to 0 I was able to connect from computers on the LAN
to the VPN, of course with the redirects 'n stuff in pf.conf. Seems that
pf's code have higher priority than that kernel's stuff :+/
Salu2.
Javier Villavicencio.