Quote from: userfw on September 18, 2026, 02:51:58 PMThe problem with null routing is that it breaks policy based site-to-site VPNs
If you are able to reconfigure your IPSEC policy based VPN's to use VTI's, you may overcome the discarded packets.
If anyone on this list has used the 'return' or 'return-icmp' option in their pf firewall rules for ICMP packets, they may be able to advise which versions of OPNsense / FreeBSD it was known to work in.
You could file a bug report with FreeBSD.
[Update] Alternatively, you may be able to set up a UDP ping between the hosts and react on the responses received.
"