A little more information that I have dug up.
This is from the last 50 filter log entries: Oct 7 00:09:27 wil-firewall ipmon[130]: 00:09:26.683887 sis0 @0:29 b 209.60.x.x,2021 -> 172.16.x.x,5060 PR tcp len 20 48 -S IN NAT
And here is the rule that is blocking from ipfstat -nio: @29 block in log quick on sis0 all head 200
and here is the ipnat -lv: rdr sis0 0.0.0.0/0 port 5060 -> 172.16.x.x port 5060 tcp/udp
|