On Thu, Feb 26, 2015 at 05:02:48PM -0500, Ted Unangst wrote:
> D'Arcy J.M. Cain wrote:
> > On Thu, 26 Feb 2015 15:22:36 -0500
> > "Ted Unangst" <[email protected]> wrote:
> > > Well, there's what should happen and what does happen. The behavior
> > > described sounds a lot like it's keeping state. You can check with
> > > pfctl -ss.
> >
> > all udp 98.158.139.74:5060 <- 207.35.13.14:5060 MULTIPLE:MULTIPLE
> >
> > What does "MULTIPLE:MULTIPLE" mean?
>
> multiple packets have passed, in both directions. i.e., you have a state.
Add -v and you'll see which rule created that state.
-Otto