Kernel gates that let unencrypted tunnels pass traffic. OpenBSD ships them off; enable a gate only for the tunnel types you run. These tunnels are unauthenticated, so also firewall the encapsulation protocol to the peer. Changes are applied now and persisted to /etc/sysctl.conf.