1match log (matches) inet proto tcp all 2match log (matches) inet from 192.0.2.0/24 to any 3pass all flags S/SA keep state 4