>What are your settings for > > $ sysctl -a | grep bridge.pfil
#bridge options net.link.bridge.pfil_onlyip=1 net.link.bridge.pfil_member=1 net.link.bridge.pfil_bridge=0 > Have you tried filtering only on one of the physical bridge interfaces, > with net.link.bridge.pfil_bridge=0 and set skip on { lo0, bridge0, em1 }? I've only been filtering on one of the bridge interfaces , however I have not 'set skip on' the other interfaces. I will try that. _______________________________________________ freebsd-pf@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-pf To unsubscribe, send any mail to "freebsd-pf-unsubscr...@freebsd.org"