Subject: Re: Non-IPSec Processing Point for ipf
To: Martin Husemann <martin@duskware.de>
From: None <itojun@iijlab.net>
List: tech-net
Date: 04/17/2003 17:57:02
>>     block in log on ex0_noipsec all head 110
>Maybe it can be made slightly more general by adding canonical tap/filter
>only interfaces and making "tap0" attach to "ex0" at tap point "noipsec"
>with a userland utility and then 

	additional interface breaks IPv6 scoping.  please don't do that.

itojun