On So, 17 Okt 2004, Oliver Humpage wrote:

> State only works on the interface on which it was created. You will
> need another keep state rule on the external interface allowing
> packets out.

pf.conf(5) says that state is floating by default. So in my opinion it
should not be necessary to add an additional pass out rule.

Could it be that nat on the external interface can prevent state
matching?

Ralf.

Reply via email to