>You forgot to specify the IV for the transforms. PF_ENCAP was >able to do IV-less mode by deriving an IV from the packet headers. >We dont do that any more with PFKEYv2. >So just modify your scripts to include a -iv line: hm? Doesn't specifying an -iv option now give you a "option is depreciated" warning? Your comment seems to indicate the opposite. -kj