Enable altq, select RED, and configure it for ECN. I'm not clear on
current altq status, so this might be off.
See also:
net.inet.ipsec.ecn = 0
net.inet6.ipsec6.ecn = 0
if you are using IPsec tunnel mode, but I'm not sure the code is there
(haven't looked).
--
Greg Troxel <gdt@ir.bbn.com>