Debugging IPsec Enable logging of IKE packets in isakmpd(8) Start it with: isakmpd -L -K Or at runtime: echo "p on" > /var/run/isakmpd.fifo Run tcpdump -vvr /var/run/isakmpd.pcap Let ipsecctl(8) show the PF_KEY messages from the kernel: ipsecctl -m