pf by design drops packets with IP options. I am seeing quite a few of those packets on one of my systems. Is there a way to tell pf to log those packets and if so, how do I identify them in the tcpdump output? -- Doug