pf changes logging subsystem rewritten match log(matches) allows rule traces pflog(4) now includes the original addresses and ports for NAT 13:41:09.452468 rule 164/(match) [uid 0, pid 8097] pass out on em0: [orig src 192.168.214.198:2217, dst 85.224.47.18:80] 81.209.197.241.60973 > 85.224.47.18.80: ...