And that means you're passing IPv6 connections without creating state. Check your ruleset, are there any 'pass' rules without 'keep state', especially for IPv6 (or without any inet/inet6 option)?
Daniel
Yes, it's be right with 'keep state' in rule my mistake, sorry
thank You very much. nobody
