Hi Scott,
As per your request I run it with the following result.
##############
$ pfctl -vvsa | grep 316
@316 pass in quick on ng0 inet proto ah from 194.143.xxx.yyy to 87.97.aaa.bbb keep state label "IPSEC: OfficeDMZ - inbound ah proto"
##############
…BUT ... probably it is not the same rule #316 anymore. (It seem to me changes time to time, maybe when I reboot.)
Meanwhile I solved it, so that I created an
" UDP * 68 * 67 *" rule on my OPT1 (ath0) interface.
I don't know what security hole creates it, if any?
I don't know that after applying your new filter.inc yesterday night, why worked without this rule?
Is ARP filtering is on when interface is bridged?
This static arp enabling is on the dhcp server tab originally, but since now it is bridged, that's no more available.
(Of course it is enabled on LAN as well)