# pfctl -sn
nat-anchor "pftpx/*" all
nat-anchor "natearly/*" all
nat-anchor "natrules/*" all
nat on nfe0 inet from 192.168.2.0/24 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on ng0 inet from 192.168.2.0/24 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on nfe0 inet from 192.168.2.0/24 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on ng0 inet from 192.168.2.0/24 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on nfe0 inet from 192.168.2.0/24 to any -> (ng0) port 1024:65535 round-robin
nat on ng0 inet from 192.168.2.0/24 to any -> (ng0) port 1024:65535 round-robin
nat on nfe0 inet from 83.219.143.131 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on ng0 inet from 83.219.143.131 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on nfe0 inet from 83.219.143.131 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on ng0 inet from 83.219.143.131 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on nfe0 inet from 83.219.143.131 to any -> (ng0) port 1024:65535 round-robin
nat on ng0 inet from 83.219.143.131 to any -> (ng0) port 1024:65535 round-robin
nat on nfe0 inet from 83.219.150.208 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on ng0 inet from 83.219.150.208 port = isakmp to any port = isakmp -> (ng0) port 500 round-robin
nat on nfe0 inet from 83.219.150.208 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on ng0 inet from 83.219.150.208 port = 5060 to any port = 5060 -> (ng0) port 5060 round-robin
nat on nfe0 inet from 83.219.150.208 to any -> (ng0) port 1024:65535 round-robin
nat on ng0 inet from 83.219.150.208 to any -> (ng0) port 1024:65535 round-robin
rdr-anchor "pftpx/*" all
rdr-anchor "slb" all
no rdr on vr1 proto tcp from any to <vpns> port = ftp
no rdr on vr1 proto tcp from <onetoonelist> to any port = ftp
rdr on vr1 inet proto tcp from any to any port = ftp -> 127.0.0.1 port 8022
no rdr on vlan1 proto tcp from any to <vpns> port = ftp
no rdr on vlan1 proto tcp from <onetoonelist> to any port = ftp
rdr on vlan1 inet proto tcp from any to any port = ftp -> 127.0.0.1 port 8023
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = ssh -> 192.168.2.5
rdr on ng0 inet proto tcp from any to any port = http -> 192.168.2.5
rdr on ng0 inet proto udp from any to any port = http -> 192.168.2.5
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = smtp -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = 7025 -> 192.168.2.11
rdr on ng0 inet proto udp from any to 83.219.150.169 port = 7025 -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = rtsp -> 192.168.2.201
rdr on ng0 inet proto udp from any to 83.219.150.169 port = rtsp -> 192.168.2.201
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = 7780 -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = submission -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = pop3s -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = https -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = pop3 -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = https -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = hosts2-ns -> 192.168.2.11 port 80
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = 31283 -> 192.168.2.99
rdr on ng0 inet proto udp from any to 83.219.150.169 port = 31283 -> 192.168.2.99
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = imap -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = smtps -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = 5060 -> 192.168.2.4
rdr on ng0 inet proto udp from any to 83.219.150.169 port = 5060 -> 192.168.2.4
rdr on ng0 inet proto tcp from any to 83.219.150.169 port 9000:9015 -> 192.168.2.4 port 9049:9064
rdr on ng0 inet proto udp from any to 83.219.150.169 port 9000:9015 -> 192.168.2.4 port 9049:9064
rdr on ng0 inet proto udp from any to 83.219.150.169 port 10000:20000 -> 192.168.2.4 port 10000:20000
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = domain -> 192.168.2.11
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = ftp -> 192.168.2.250
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = ftp-data -> 192.168.2.250
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = blackjack -> 192.168.2.250
rdr on ng0 inet proto tcp from any to 83.219.150.169 port = 1026 -> 192.168.2.250
rdr on ng0 inet proto udp from any to ! (ng0) port = 5060 -> 127.0.0.1 port 5060
rdr-anchor "imspector" all
rdr-anchor "miniupnpd" all
binat on vr1 inet from 192.168.2.11 to any -> 83.219.143.131