используется pf с такими правилами:
pass in quick on $ext_if proto tcp from < > to { } port { } flags S/SA
modulate state
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://nginx.org/pipermail/nginx-ru/attachments/20080516/81a86f96/attachment.html>