Do I need the 2nd no nat rule or is it just extra and in the way?
WAN = "xl0" LAN = "xl1" LAN2 = "xl2"
no nat from $LAN to $LAN2 no nat from $LAN2 to $LAN nat on $WAN inet from 192.168.0.0/24 to any -> ($WAN) nat on $WAN inet from 10.0.0.0/16 to any -> ($WAN)
Unless I am missing something, you do not need any of the "no nat" rules.
You are, after all, only doing nat on $WAN, and packets moving between
$LAN and $LAN2 never touch $WAN.
