> # DMZ Host > rdr on $red_if proto tcp from any to any port $dmz_ports -> $dmz_host
This doesn't look right. If you redirect all connections on those ports to the DMZ host, how do you expect your router to receive replies to those unprivileged ($dmz_ports) ports for stuff like web browsing? Kian

