Just wanted to inform you that I made it work. There has to be a policy
for every network. In m0n0wal this is very simply done by producing a
couple of tunnel entries each pointing to one of those nets (either
"local subnet" or "remote subnet" - depends which side you are at).
In "normal FreeBSD" it's done quite the same way; only one tunnel device
(gif in my case) and two "spdadd"-lines for each net.
Peter Guhl <pgnews at siconline dot ch>