Matthew Dillon wrote:
I'm pretty sure we have tagging support, but as far as I can tell
there is no way to associate a tag with the keep-state PF uses to
track a connection.
based on pf.conf I was wrong here - I was getting generic tagging support confused with ethernet address tagging from bridge ineterfaces..
http://www.openbsd.org/faq/pf/tagging.html#ethernet which would have nothing to do with the problem here..
