diff --git a/src/etc/config.xml.sample b/src/etc/config.xml.sample
index 24f08ea62..1fee600ac 100644
--- a/src/etc/config.xml.sample
+++ b/src/etc/config.xml.sample
@@ -108,11 +108,6 @@
net.inet.tcp.sendspace
default
- -
-
- net.inet.ip.fastforwarding
- default
-
-
net.inet.tcp.delayed_ack
diff --git a/src/etc/inc/plugins.inc.d/ipsec.inc b/src/etc/inc/plugins.inc.d/ipsec.inc
index b96c7810b..3ea481d77 100644
--- a/src/etc/inc/plugins.inc.d/ipsec.inc
+++ b/src/etc/inc/plugins.inc.d/ipsec.inc
@@ -766,9 +766,6 @@ function ipsec_configure_do($verbose = false, $interface = '')
echo 'Configuring IPsec VPN...';
}
- /* fastforwarding is not compatible with ipsec tunnels */
- set_single_sysctl("net.inet.ip.fastforwarding", "0");
-
/* resolve all local, peer addresses and setup pings */
$rgmap = array();
$filterdns_list = array();
diff --git a/src/etc/inc/system.inc b/src/etc/inc/system.inc
index 8c6535c45..e881a8a65 100644
--- a/src/etc/inc/system.inc
+++ b/src/etc/inc/system.inc
@@ -96,7 +96,6 @@ function get_default_sysctl_value($id)
"net.inet.tcp.syncookies" => "1",
"net.inet.tcp.recvspace" => "65228",
"net.inet.tcp.sendspace" => "65228",
- "net.inet.ip.fastforwarding" => "0",
'net.inet.ip.sourceroute' => '0',
'net.inet.ip.accept_sourceroute' => '0',
'net.inet.icmp.drop_redirect' => '0',