Hello, In the changelog from 4.0 to 4.1, I read: # In pf.conf(5), make 'flags S/SA keep state' the implicit default for filter rules.
Does this only apply to tcp (as suggested by the flags) or to all protocols? Also, is there a way to specify that there should be no state kept? I am trying to make pptp VPN pass through my nat firewall, it worked great with 3.9 and is not working anymore with 4.1. I know that when I put a keep state for GRE protocol it didn't work and without the keep state it worked, but that may be unrelated. Regards

