@0(0) scrub on mvneta2 all fragment reassemble
  [ Evaluations: 6         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@1(0) scrub on mvneta1 all fragment reassemble
  [ Evaluations: 6         Packets: 5         Bytes: 174         States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@0(0) anchor "openvpn/*" all
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@1(0) anchor "ipsec/*" all
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@2(1000000101) block drop in log quick inet from 169.254.0.0/16 to any label "Block IPv4 link-local"
  [ Evaluations: 196       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@3(1000000102) block drop in log quick inet from any to 169.254.0.0/16 label "Block IPv4 link-local"
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@4(1000000103) block drop in log inet all label "Default deny rule IPv4"
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@5(1000000104) block drop out log inet all label "Default deny rule IPv4"
  [ Evaluations: 195       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@6(1000000105) block drop in log inet6 all label "Default deny rule IPv6"
  [ Evaluations: 196       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@7(1000000106) block drop out log inet6 all label "Default deny rule IPv6"
  [ Evaluations: 100       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@8(1000000107) pass quick inet6 proto ipv6-icmp all icmp6-type unreach keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@9(1000000107) pass quick inet6 proto ipv6-icmp all icmp6-type toobig keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@10(1000000107) pass quick inet6 proto ipv6-icmp all icmp6-type neighbrsol keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@11(1000000107) pass quick inet6 proto ipv6-icmp all icmp6-type neighbradv keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@12(1000000108) pass out quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type echorep keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@13(1000000108) pass out quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type routersol keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@14(1000000108) pass out quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type routeradv keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@15(1000000108) pass out quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type neighbrsol keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@16(1000000108) pass out quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type neighbradv keep state
  [ Evaluations: 4         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@17(1000000109) pass out quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type echorep keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@18(1000000109) pass out quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type routersol keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@19(1000000109) pass out quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type routeradv keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@20(1000000109) pass out quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type neighbrsol keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@21(1000000109) pass out quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type neighbradv keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@22(1000000110) pass in quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type echoreq keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@23(1000000110) pass in quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type routersol keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@24(1000000110) pass in quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type routeradv keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@25(1000000110) pass in quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type neighbrsol keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@26(1000000110) pass in quick inet6 proto ipv6-icmp from fe80::/10 to fe80::/10 icmp6-type neighbradv keep state
  [ Evaluations: 3         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@27(1000000111) pass in quick inet6 proto ipv6-icmp from ff02::/16 to fe80::/10 icmp6-type echoreq keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@28(1000000111) pass in quick inet6 proto ipv6-icmp from ff02::/16 to fe80::/10 icmp6-type routersol keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@29(1000000111) pass in quick inet6 proto ipv6-icmp from ff02::/16 to fe80::/10 icmp6-type routeradv keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@30(1000000111) pass in quick inet6 proto ipv6-icmp from ff02::/16 to fe80::/10 icmp6-type neighbrsol keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@31(1000000111) pass in quick inet6 proto ipv6-icmp from ff02::/16 to fe80::/10 icmp6-type neighbradv keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@32(1000000112) pass in quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type echoreq keep state
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@33(1000000112) pass in quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type routersol keep state
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@34(1000000112) pass in quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type routeradv keep state
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@35(1000000112) pass in quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type neighbrsol keep state
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@36(1000000112) pass in quick inet6 proto ipv6-icmp from fe80::/10 to ff02::/16 icmp6-type neighbradv keep state
  [ Evaluations: 1         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@37(1000000113) pass in quick inet6 proto ipv6-icmp from :: to ff02::/16 icmp6-type echoreq keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@38(1000000113) pass in quick inet6 proto ipv6-icmp from :: to ff02::/16 icmp6-type routersol keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@39(1000000113) pass in quick inet6 proto ipv6-icmp from :: to ff02::/16 icmp6-type routeradv keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@40(1000000113) pass in quick inet6 proto ipv6-icmp from :: to ff02::/16 icmp6-type neighbrsol keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@41(1000000113) pass in quick inet6 proto ipv6-icmp from :: to ff02::/16 icmp6-type neighbradv keep state
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@42(1000000114) block drop log quick inet proto tcp from any port = 0 to any label "Block traffic from port 0"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@43(1000000114) block drop log quick inet proto udp from any port = 0 to any label "Block traffic from port 0"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@44(1000000115) block drop log quick inet proto tcp from any to any port = 0 label "Block traffic to port 0"
  [ Evaluations: 192       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@45(1000000115) block drop log quick inet proto udp from any to any port = 0 label "Block traffic to port 0"
  [ Evaluations: 192       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@46(1000000116) block drop log quick inet6 proto tcp from any port = 0 to any label "Block traffic from port 0"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@47(1000000116) block drop log quick inet6 proto udp from any port = 0 to any label "Block traffic from port 0"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@48(1000000117) block drop log quick inet6 proto tcp from any to any port = 0 label "Block traffic to port 0"
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@49(1000000117) block drop log quick inet6 proto udp from any to any port = 0 label "Block traffic to port 0"
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@50(1000000118) block drop log quick from <snort2c:0> to any label "Block snort2c hosts"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@51(1000000119) block drop log quick from any to <snort2c:0> label "Block snort2c hosts"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@52(1000000301) block drop in log quick proto tcp from <sshguard:0> to (self:7) port = ssh label "sshguard"
  [ Evaluations: 194       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@53(1000000351) block drop in log quick proto tcp from <sshguard:0> to (self:7) port = https label "GUI Lockout"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@54(1000000400) block drop in log quick from <virusprot:0> to any label "virusprot overload table"
  [ Evaluations: 342       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@55(1000000561) pass in quick on mvneta2 proto udp from any port = bootps to any port = bootpc keep state label "allow dhcp client out WAN"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@56(1000000562) pass out quick on mvneta2 proto udp from any port = bootpc to any port = bootps keep state label "allow dhcp client out WAN"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@57(1000002620) block drop in log on mvneta1 inet6 from fe80::208:a2ff:fe0d:b7d7 to any
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@58(1000002620) block drop in log on mvneta1 inet6 from fe80::1:1 to any
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@59(1000002620) block drop in log on ! mvneta1 inet from 192.168.1.0/24 to any
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@60(1000002620) block drop in log inet from 192.168.1.1 to any
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@61(1000002641) pass in quick on mvneta1 inet proto udp from any port = bootpc to 255.255.255.255 port = bootps keep state label "allow access to DHCP server"
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@62(1000002642) pass in quick on mvneta1 inet proto udp from any port = bootpc to 192.168.1.1 port = bootps keep state label "allow access to DHCP server"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@63(1000002643) pass out quick on mvneta1 inet proto udp from 192.168.1.1 port = bootps to any port = bootpc keep state label "allow access to DHCP server"
  [ Evaluations: 98        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@64(1000002651) pass quick on mvneta1 inet6 proto udp from fe80::/10 to fe80::/10 port = dhcpv6-client keep state label "allow access to DHCPv6 server"
  [ Evaluations: 2         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@65(1000002652) pass quick on mvneta1 inet6 proto udp from fe80::/10 to ff02::/16 port = dhcpv6-client keep state label "allow access to DHCPv6 server"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@66(1000002653) pass quick on mvneta1 inet6 proto udp from fe80::/10 to ff02::/16 port = dhcpv6-server keep state label "allow access to DHCPv6 server"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@67(1000002654) pass quick on mvneta1 inet6 proto udp from ff02::/16 to fe80::/10 port = dhcpv6-server keep state label "allow access to DHCPv6 server"
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@68(1000002661) pass in on lo0 inet all flags S/SA keep state label "pass IPv4 loopback"
  [ Evaluations: 194       Packets: 192       Bytes: 13792       States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@69(1000002662) pass out on lo0 inet all flags S/SA keep state label "pass IPv4 loopback"
  [ Evaluations: 192       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@70(1000002663) pass in on lo0 inet6 all flags S/SA keep state label "pass IPv6 loopback"
  [ Evaluations: 192       Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@71(1000002664) pass out on lo0 inet6 all flags S/SA keep state label "pass IPv6 loopback"
  [ Evaluations: 96        Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@72(1000002665) pass out inet all flags S/SA keep state allow-opts label "let out anything IPv4 from firewall host itself"
  [ Evaluations: 194       Packets: 192       Bytes: 13792       States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@73(1000002666) pass out inet6 all flags S/SA keep state allow-opts label "let out anything IPv6 from firewall host itself"
  [ Evaluations: 98        Packets: 6         Bytes: 456         States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@74(10000) pass in quick on mvneta1 proto tcp from any to (mvneta1:3) port = https flags S/SA keep state label "anti-lockout rule"
  [ Evaluations: 673       Packets: 199       Bytes: 83485       States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@75(10000) pass in quick on mvneta1 proto tcp from any to (mvneta1:3) port = http flags S/SA keep state label "anti-lockout rule"
  [ Evaluations: 673       Packets: 199       Bytes: 83485       States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@76(0) anchor "userrules/*" all
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@77(100000101) pass in quick on mvneta1 inet from 192.168.1.0/24 to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"
  [ Evaluations: 666       Packets: 6         Bytes: 1765        States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
@78(0) anchor "tftp-proxy/*" all
  [ Evaluations: 0         Packets: 0         Bytes: 0           States: 0     ]
  [ Inserted: pid 65139 State Creations: 0     ]
