When the traffic has passed the internal interface and has been tagged by the quick rule, it will be forwarded to the either the external interface, or the DMZ interface.
There it will be subject to further processing by pf e.g. pass out quick on $dmz tagged LAN_TO_DMZ
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|