How about using the zone file I posted in http://daemonforums.org/showpost.php?p=3927&postcount=9 ?
Don't forget the named log file for any errors
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|