am I being daft on this one? pfctl passes a syntax check on a rule such as this:
pass out on $DMZ_if \ inet proto icmp   \ from 192.168.99.68  but not this: pass out on $DMZ_if \ inet proto icmp icmp-type unreach  \ from 192.168.99.68 this is ok: pass out on $DMZ_if \ inet proto icmp icmp-type $icmp-type_list I'm resorting to having separate pass rules for localnet_if in and dmz_if out is this ok? am I missing something? regards