Question: Why does tcpdump show pf rules when I use the pflog0 interface in combination with the -e switch (link layer)? It's a fantastic feature but it seems like an odd way to arrive at it.
rule 0/(match) [uid 0, pid 14885] pass out on fxp0: esp 192.168.1.1 > 192.168.2.213 spi 0x00001 -- Peter __________________________________________________________ Find your next car at http://autos.yahoo.ca