root@opnsense:~ # pfctl -s nat | grep -i '^rdr .* port = domain'rdr on vlan0.5 inet proto tcp from any to ! (self) port = domain -> 10.1.5.1 port 53rdr on vlan0.5 inet proto udp from any to ! (self) port = domain -> 10.1.5.1 port 53root@opnsense:~ #
even if the source field contains a "superset" of the subnets of those interfaces.