@xcrustwadx:
I also was unable to find records of upnp traffic in pftop either… I didn't think it was possible to bypass pf.
You aren't, the rules go into the upnp anchor, which is probably above your normal rules, hence the reason you can't override it. I think we'd be willing to see a patch that moves it below user rules and doesn't regress anything ;) In the meantime, I run upnp on ONLY a trusted interface with very little else on it (that poor xbox is quite lonely, but it does have the Wii and my torrent machine for company at least).
–Bill