... if you really want a firewall you need pfSense. Also if you " walk into any security experts convention and claim that raw OpenBSD is "a firewall", you will get laughed out of the room for lack of clue."
Guess I've been wrong all these years: see the comments to https://plus.google.com/u/0/104027218792812194992/posts/K3NsGE2UrCe