On 2012-06-26, Илья Шипицин <chipits...@gmail.com> wrote: > match in inet proto tcp from any port = ftp-data to $external port > 1024:65535 rdr-to $internal port 1024:65535
You know people can choose their own source port number? It's just as safe to do "from any to $external port 1024:65535"...