der Mouse wrote:
> I find myself needing to encapsulate IP in TCP, for reasons not really
> worth going into here (the principal part is a NAT box whose
> configuration is out of my control).
> [...]
> This is being done on NetBSD; in particular, I have source, so things
> that involve hacking on the encapsulation endpoint TCP stacks are not
> out of the question.

Have you considered vtun, which can also handle tunnels over tcp?