Only for direction in, you cant handle local initiated packets
root@LDC01A:~ # pfctl -sr | grep em0_vlan910|grep "pass out"pass out route-to (em0_vlan910 10.100.2.254) inet from (em0_vlan910) to ! (em0_vlan910:network) flags S/SA keep state allow-opts label "b063dd13c292c33ec96318589a8e95f4"pass out route-to (em0_vlan910 10.100.2.254) sticky-address inet from (em0_vlan910) to <tdc01lan> flags S/SA keep state label "d86945c81601734ff34ae06caeb54e6e"