@0 scrub from any to <vpn_networks:1> fragment no reassemble
  [ Evaluations: 39278     Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@1 scrub from <vpn_networks:1> to any fragment no reassemble
  [ Evaluations: 39278     Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@2 scrub on em0 inet all fragment reassemble
  [ Evaluations: 39278     Packets: 37290     Bytes: 7214797     States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@3 scrub on em0 inet6 all fragment reassemble
  [ Evaluations: 89        Packets: 89        Bytes: 9196        States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@4 scrub on ipsec1 inet all fragment reassemble
  [ Evaluations: 9         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@5 scrub on ipsec1 inet6 all fragment reassemble
  [ Evaluations: 3         Packets: 3         Bytes: 244         States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@0 anchor "openvpn/*" all
  [ Evaluations: 5068      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@1 anchor "ipsec/*" all
  [ Evaluations: 5068      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@2 pass in quick on lo0 inet6 all flags S/SA keep state (if-bound) label "descr=pass IPv6 loopback" ridentifier 1000000001
  [ Evaluations: 5068      Packets: 23        Bytes: 2488        States: 1     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 6     ]
  [ Last Active Time: Fri Jun  5 11:49:50 2026 ]
@3 pass out quick on lo0 inet6 all flags S/SA keep state (if-bound) label "descr=pass IPv6 loopback" ridentifier 1000000002
  [ Evaluations: 40        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@4 block drop in log quick inet6 all label "descr=Block all IPv6" ridentifier 1000000003
  [ Evaluations: 4966      Packets: 46        Bytes: 4748        States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: Fri Jun  5 11:49:57 2026 ]
@5 block drop out log quick inet6 all label "descr=Block all IPv6" ridentifier 1000000004
  [ Evaluations: 3263      Packets: 95        Bytes: 8676        States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: Fri Jun  5 11:49:50 2026 ]
@6 block drop in log quick inet6 from any to <_nat64reserved_:16> label "descr=Block NAT64 for non-global IPv4" ridentifier 1000000005
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@7 block drop out log quick inet6 from any to <_nat64reserved_:16> label "descr=Block NAT64 for non-global IPv4" ridentifier 1000000006
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@8 block drop in log quick inet from 169.254.0.0/16 to any label "descr=Block IPv4 link-local" ridentifier 1000000101
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@9 block drop in log quick inet from any to 169.254.0.0/16 label "descr=Block IPv4 link-local" ridentifier 1000000102
  [ Evaluations: 1697      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@10 block drop in log inet all label "descr=Default deny rule IPv4" label "tags=ruleset:e85581c4c9f01147" ridentifier 1000000103
  [ Evaluations: 309       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@11 block drop out log inet all label "descr=Default deny rule IPv4" label "tags=ruleset:e85581c4c9f01147" ridentifier 1000000104
  [ Evaluations: 923       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@12 block drop in log inet6 all label "descr=Default deny rule IPv6" label "tags=ruleset:e85581c4c9f01147" ridentifier 1000000105
  [ Evaluations: 923       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@13 block drop out log inet6 all label "descr=Default deny rule IPv6" label "tags=ruleset:e85581c4c9f01147" ridentifier 1000000106
  [ Evaluations: 614       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@14 block drop log quick inet proto tcp from any port = 0 to any label "descr=Block traffic from port 0" ridentifier 1000000107
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@15 block drop log quick inet proto udp from any port = 0 to any label "descr=Block traffic from port 0" ridentifier 1000000107
  [ Evaluations: 4810      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@16 block drop log quick inet proto tcp from any to any port = 0 label "descr=Block traffic to port 0" ridentifier 1000000108
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@17 block drop log quick inet proto udp from any to any port = 0 label "descr=Block traffic to port 0" ridentifier 1000000108
  [ Evaluations: 4810      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@18 block drop log quick from <snort2c:0> to any label "descr=Block snort2c hosts" ridentifier 1000000109
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@19 block drop log quick from any to <snort2c:0> label "descr=Block snort2c hosts" ridentifier 1000000110
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@20 block drop in log quick proto carp from (self:9) to any label "descr=CARP operation" ridentifier 1000000201
  [ Evaluations: 4905      Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@21 pass quick proto carp all no state label "descr=CARP operation" ridentifier 1000000202
  [ Evaluations: 4809      Packets: 4509      Bytes: 252504      States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: Fri Jun  5 11:49:59 2026 ]
@22 block drop in log quick proto tcp from <sshguard:0> to (self:9) port = ssh label "descr=sshguard" ridentifier 1000000301
  [ Evaluations: 396       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@23 block drop in log quick proto tcp from <sshguard:0> to (self:9) port = https label "descr=GUI Lockout" ridentifier 1000000351
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@24 block drop in log quick from <virusprot:0> to any label "descr=virusprot overload table" ridentifier 1000000400
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@25 block drop out quick proto udp from any port = bootps to any port = bootpc label "descr=Prevent routing dhcp responses" ridentifier 1000000451 tagged dhcpin
  [ Evaluations: 396       Packets: 1         Bytes: 322         States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@26 pass in quick on em0 proto udp from any port = bootps to any port = bootpc no state label "descr=allow dhcp replies in WAN" ridentifier 1000000461 tag dhcpin
  [ Evaluations: 96        Packets: 4         Bytes: 1288        States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@27 pass out quick on em0 proto udp from any port = bootpc to any port = bootps no state label "descr=allow dhcp client out WAN" ridentifier 1000000462
  [ Evaluations: 249       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@28 block drop in log on ! em0 inet from 192.168.254.0/24 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 102       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@29 block drop in log on ! em0 inet from 192.168.254.34 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@30 block drop in log on ! em0 inet from 192.168.254.33 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@31 block drop in log on em0 inet6 from fe80::a00:27ff:fed4:3e55 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 99        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@32 block drop in log inet from 192.168.254.25 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 21        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@33 block drop in log inet from 192.168.254.34 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 21        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@34 block drop in log inet from 192.168.254.33 to any label "descr=antispoof protection" ridentifier 1000001471
  [ Evaluations: 21        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@35 block drop in log on ! ipsec1 inet from 10.15.0.0/30 to any label "descr=antispoof protection" ridentifier 1000002521
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@36 block drop in log on ipsec1 inet6 from fe80::a00:27ff:fed4:3e55 to any label "descr=antispoof protection" ridentifier 1000002521
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@37 block drop in log inet from 10.15.0.2 to any label "descr=antispoof protection" ridentifier 1000002521
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@38 pass in on lo0 inet all flags S/SA keep state (if-bound) label "descr=pass IPv4 loopback" ridentifier 1000004661
  [ Evaluations: 131       Packets: 206       Bytes: 62632       States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@39 pass out on lo0 inet all flags S/SA keep state (if-bound) label "descr=pass IPv4 loopback" ridentifier 1000004662
  [ Evaluations: 303       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@40 pass out inet all flags S/SA keep state (if-bound) allow-opts label "descr=let out anything IPv4 from firewall host itself" ridentifier 1000004663
  [ Evaluations: 349       Packets: 1963      Bytes: 371066      States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@41 pass out route-to (em0 192.168.254.10) inet from 192.168.254.25 to ! 192.168.254.0/24 flags S/SA keep state (if-bound) allow-opts label "descr=let out anything from firewall host itself" ridentifier 1000004761
  [ Evaluations: 81        Packets: 136       Bytes: 24039       States: 2     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 34    ]
  [ Last Active Time: Fri Jun  5 11:49:53 2026 ]
@42 pass out route-to (em0 192.168.254.10) inet from 192.168.254.33 to ! 192.168.254.0/24 flags S/SA keep state (if-bound) allow-opts label "descr=let out anything from firewall host itself" ridentifier 1000004762
  [ Evaluations: 74        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@43 pass out route-to (em0 192.168.254.10) inet from 192.168.254.34 to ! 192.168.254.0/24 flags S/SA keep state (if-bound) allow-opts label "descr=let out anything from firewall host itself" ridentifier 1000004763
  [ Evaluations: 74        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@44 pass out inet from 10.15.0.2 to ! 10.15.0.0/30 flags S/SA keep state (if-bound) allow-opts label "descr=let out anything from firewall host itself" ridentifier 1000004764
  [ Evaluations: 34        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@45 pass out on enc0 all flags S/SA keep state label "descr=IPsec internal host to host" ridentifier 1000005062
  [ Evaluations: 299       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@46 pass out on ipsec1 all flags S/SA keep state label "descr=IPsec VTI floating states" ridentifier 1000005063
  [ Evaluations: 299       Packets: 24        Bytes: 7528        States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@47 pass in quick on ipsec1 proto tcp from any to (ipsec1:2) port = https flags S/SA keep state (if-bound) label "descr=anti-lockout rule" ridentifier 10001
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@48 pass in quick on ipsec1 proto tcp from any to (ipsec1:2) port = http flags S/SA keep state (if-bound) label "descr=anti-lockout rule" ridentifier 10001
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@49 anchor "userrules/*" all
  [ Evaluations: 389       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@50 pass in quick on em0 reply-to (em0 192.168.254.10) inet all flags S/SA keep state (if-bound) label "id=1778676401" label "tags=user_rule" ridentifier 1778676401
  [ Evaluations: 102       Packets: 1708      Bytes: 1245328     States: 2     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 2     ]
  [ Last Active Time: Fri Jun  5 11:49:51 2026 ]
@51 pass in quick on ipsec1 reply-to (ipsec1 10.15.0.1) inet from <LAN__NETWORK:1> to any flags S/SA keep state (if-bound) label "id=0100000101" label "tags=user_rule" label "descr=Default allow LAN to any rule" ridentifier 100000101
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@52 pass in quick on ipsec1 inet6 from <LAN__NETWORK:1> to any flags S/SA keep state (if-bound) label "id=0100000102" label "tags=user_rule" label "descr=Default allow LAN IPv6 to any rule" ridentifier 100000102
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@53 pass out inet proto udp from (self:5) to 192.168.254.21 port = isakmp keep state (if-bound) label "descr=IPsec: 192.168.254.21 - outbound isakmp" ridentifier 1000105201
  [ Evaluations: 60        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@54 pass in on em0 inet proto udp from 192.168.254.21 to (self:5) port = isakmp keep state (if-bound) label "descr=IPsec: 192.168.254.21 - inbound isakmp" ridentifier 1000105202
  [ Evaluations: 55        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@55 pass out inet proto udp from (self:5) to 192.168.254.21 port = ipsec-nat-t keep state (if-bound) label "descr=IPsec: 192.168.254.21 - outbound nat-t" ridentifier 1000105203
  [ Evaluations: 55        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@56 pass in on em0 inet proto udp from 192.168.254.21 to (self:5) port = ipsec-nat-t keep state (if-bound) label "descr=IPsec: 192.168.254.21 - inbound nat-t" ridentifier 1000105204
  [ Evaluations: 55        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@57 pass out inet proto esp from (self:5) to 192.168.254.21 keep state (if-bound) label "descr=IPsec: 192.168.254.21 - outbound esp proto" ridentifier 1000105205
  [ Evaluations: 60        Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@58 pass in on em0 inet proto esp from 192.168.254.21 to (self:5) keep state (if-bound) label "descr=IPsec: 192.168.254.21 - inbound esp proto" ridentifier 1000105206
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
@59 anchor "tftp-proxy/*" all
  [ Evaluations: 339       Packets: 0         Bytes: 0           States: 0     ]
  [ Source Nodes: 0      Limit: 0      NAT/RDR: 0      Route: 0      ]
  [ Inserted: uid 0 pid 0 State Creations: 0     ]
  [ Last Active Time: N/A ]
