2.0 RC1 snort blocks ipsec

  • hello,

    using 2.0-RC1 (i386) built on Mon Mar 28 16:37:49 EDT 2011 on production environment,i noticed that when snort running it blocked site to site ipsec remote ip addresses.I put all of remote site ipsec ip addresses into  snort whitelist,but didn't help.Before upgrade, on pf 1.2.3 this configuration run without any problem.I restarted pf several times,any changes.Now firewall on production running without snort.Any tricks howto run snort on 2.0 RC1 with site to site ipsec?

