When you configure firewall rules you have an option to select different aliases for source, like "This Firewall", "LAN Net", "WAN addresses", etc. But those are missing when I go into pfTables, only the ones I defined are there.
How do I diagnose what they actually are?
You may think that those are equivalent to the net defined in the interface, but I have noticed that often those are not resolved this way. Where manually typing the address into the rule works, while using those aliases don't get things matched.