Hi All, Thanks to Jesper and Stuart, i'm using max-pkt-rate not!
I'm also using max-src-conn-rate and overload in conjunction with authpf and I'm worried that potentially valid traffic may get blocked. I'm wondering if it's a condoned/accepted/best practice to use cron with pfctl to expire table entries that are over a certain age. I promise I did google "cron pfctl -T expire" first and only came up with someone who wrote a script from 2014!!! Thanks in advance!