Tony Faoro wrote:

pass out on $ext_if inet proto tcp from 10.0.0.10/32 to 1.2.3.4/32 port /
5310 flags S/SA keep state queue(audio)

I'm not sure if you've just sanitized your IP addresses or not, but if you're doing NAT on $ext_if, you cannot filter outgoing packets based on internal addresses; the packets are translated before they hit the filter engine.



.joel




Reply via email to