@coreybrett
PF uses an enc0 interface to filter all ipsec traffic. (classic ipsec tunnel, VTI).
em1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
ether 08:00:27:7e:d9:81
hwaddr 08:00:27:7e:d9:81
inet6 fe80::a00:27ff:fe7e:d981%em1 prefixlen 64 scopeid 0x2
inet 10.3.100.1 netmask 0xffffff00 broadcast 10.3.100.255
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
enc0: flags=41<UP,RUNNING> metric 0 mtu 1536
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
groups: enc
Therefore, all filtering rules are created on the IPSEC tab ( including for VTI).