hello, Finally Daniel had the last word :
"A quick first guess would be that the IMAP server is not routing its replies through the pf box (i.e. the default gateway setting on the IMAP server is wrong)." By changing the default gw of my IMAP Exchange server with my testing PF Firewall, the connection from outside is ok. In conclusion I use (as written in book or internet) : rdr on $ext_if proto tcp from any to $ext_ad port 993 -> $imaps_server_ad pass in quick on $ext_if \ inet proto tcp \ from any port > 1023 to $imaps_server_ad port imaps flags S/SA modulate state Thank you all for your quick reply, regards, raphael