Use 'pfctl -vvss' to see which rule it is matching on. I bet you have a rule that matches that traffic.
On 2012 Jul 09 (Mon) at 20:34:55 +0200 (+0200), Peter J. Philipp wrote: :Hi, : :Was there any bugfixes between 5.0 and 5.1 that would allow certain packets :through the pf filter? I have a case where I cannot block a certain IP on :a 5.0 box. I tested that same IP on an 5.1 box with a spoofer and I found :my same rules to catch, so it's not my logic I don't think. : :I tested with tcpdump, netcat, and custom software. : :Any hint would be nice, : :-peter : -- 43rd Law of Computing: Anything that can go wr fortune: Segmentation violation -- Core dumped