pfctl -s nat
# pfctl -s natnat-anchor "miniupnpd" allno nat proto carp allnat on tailscale0 inet from <SiteAnet> to any -> (tailscale0:0) port 1024:65535nat on vlan0.10 inet from <ocserv_clients> to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from <SiteBnet> to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from (igc0:network) to any port = isakmp -> (vlan0.10:0) static-portnat on vlan0.10 inet from (lo0:network) to any port = isakmp -> (vlan0.10:0) static-portnat on vlan0.10 inet from (wg0:network) to any port = isakmp -> (vlan0.10:0) static-portnat on vlan0.10 inet from (vlan05:network) to any port = isakmp -> (vlan0.10:0) static-portnat on vlan0.10 inet from 127.0.0.0/8 to any port = isakmp -> (vlan0.10:0) static-portnat on vlan0.10 inet from (igc0:network) to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from (lo0:network) to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from (wg0:network) to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from (vlan05:network) to any -> (vlan0.10:0) port 1024:65535nat on vlan0.10 inet from 127.0.0.0/8 to any -> (vlan0.10:0) port 1024:65535no rdr proto carp allno rdr on igc0 proto tcp from any to (igc0) port = sshno rdr on igc0 proto tcp from any to (igc0) port = httpno rdr on igc0 proto tcp from any to (igc0) port = httpsrdr-anchor "miniupnpd" allbinat-anchor "miniupnpd" all