device crypto
options IPSec
ext_if="em0"
int_if="em1"
tun_if="gre0"
table <vpn> {a.b.c.d}
set skip on {lo0, $int_if, $tun_if}
pass out on $ext_if all keep state
pass in on $ext_if inet proto {ipencap, esp, gre} from <vpn> to $ext_if keep state
pass in on $ext_if inet proto udp from <vpn> to $ext_if port isakmp keep state