Hi, On Thu, 21.01.2010 at 21:48:01 +0000, Christian Weisgerber <na...@mips.inka.de> wrote: > Toni Mueller <openbsd-m...@oeko.net> wrote: > > today I see tons of these on a 4.6-stable/amd64 machine (sample): > > 17:21:00.848135 esp 1.1.1.1 > 2.2.2.2 spi 0x54d46678 seq 132642 len 84 > > (DF) (ttl 64, id 49897, len 104, bad cksum 0! differs by 8b3c) > > This looks like outgoing packets on an interface that does IPv4 > header checksumming in hardware. tcpdump sees the packets before > the checksum is actually filled in. This has nothing to do with > IPsec.
thanks for the explanation. I didn't think of it, but it's a bge(4) interface. Kind regards, --Toni++