>>>> I did test the folowing ruleset: >>>> pass in quick on ep0 inet from 1.2.3.1 to 10.0.0.2 keep state >>>> block drop out log quick on ep0 all >>>> pass out quick on bge0 inet proto tcp from 1.2.3.1 to 10.0.0.2 maybe "set skip on ep0" ? -- regards, Artis Caune <----. CCNA <----|==================== <----' didii FreeBSD