>А Вы ipfw list покажите.
00100 count ip from 192.168.0.0/24 to any
00200 divert 8668 udp from 10.10.9.0/24 to any 53 out recv rl0 xmit rl1
00300 divert 8668 udp from 192.168.0.0/24 to any 53 out recv rl2 xmit rl1
00400 divert 8668 udp from any 53 to me in recv rl1
00500 check-state
00600 deny icmp from any to any in icmptype 5,9,13,14,15,16,17
00700 deny ip from 10.10.9.0/24 to any in recv rl1
00800 deny ip from 192.168.0.0/24 to any in recv rl1
00900 deny ip from not 10.10.9.0/24 to any in recv rl0
01000 deny ip from not 192.168.0.0/24 to any in recv rl2
01100 allow ip from any to any via lo0
01200 deny ip from any to 127.0.0.0/8
01300 deny ip from 127.0.0.0/8 to any
01400 allow tcp from 82.144.199.16 to me 110 via rl1
01500 allow tcp from any to me 25 via rl1
01600 allow tcp from any to me 1723 via rl1
01700 allow gre from any to me via rl1
01800 allow tcp from me to any keep-state via rl1
01900 divert 8668 ip from 10.10.9.0/24 to any out recv rl0 xmit rl1
02000 divert 8668 ip from 192.168.0.0/24 to any out recv rl2 xmit rl1
02100 divert 8668 ip from any to 192.168.1.2 in recv rl1
02200 allow icmp from any to any
02300 allow udp from me to any 53 keep-state
02400 allow ip from me to any
02500 allow ip from any to 10.10.9.0/24 in recv rl1
02600 allow ip from any to 192.168.0.0/24 in recv rl1
02700 allow ip from any to any via rl0
02800 allow ip from any to any via rl2
02900 allow ip from any to any via ng0
03000 allow ip from any to any via ppp0
65535 deny ip from any to any