1 block in on eri0(!) all head 1 2 pass in on eri0(!) proto icmp from any to any group 1 3 pass out on ed0(!) all head 1000000 4 block out on ed0(!) proto udp from any to any group 1000000 5 block in on vm0(!) proto tcp/udp from any to any head 101 6 pass in inet proto tcp/udp from 1.1.1.1/32 to 2.2.2.2/32 group 101 7 pass in inet proto tcp from 1.0.0.1/32 to 2.0.0.2/32 group 101 8 pass in inet proto udp from 2.0.0.2/32 to 3.0.0.3/32 group 101 9 block in on vm0(!) proto tcp/udp from any to any head vm0-group 10 pass in inet proto tcp/udp from 1.1.1.1/32 to 2.2.2.2/32 group vm0-group 11 block in on vm0(!) proto tcp/udp from any to any head vm0-group 12 pass in inet proto tcp/udp from 1.1.1.1/32 to 2.2.2.2/32 group vm0-group 13 pass in inet6 from 8f::/128 to f8::/128 14 block in inet6 proto udp from any to any 15 block in inet6 all 16