I'm glad you discovered your problem was misconfigured NAT rules.
I do not understand what you are asking, now, regarding your 192.168.1 LAN. As you have crafted your pf.conf, you have pass in and pass out rules by individual system. If you want filter rules by interface or network, you can certainly write them.
|