I've been having the same problem for the past few days now and my research has turned up a few people experiencing the exact same thing that you are, across different versions of pf on different operating systems.
A few references I found off hand: http://www.mail-archive.com/misc@openbsd.org/msg30646.html http://openbsd.7691.n7.nabble.com/PF-question-set-block-policy-drop-spoofed-ip-NAT-ed-elicits-icmp-unreachable-tt14709.html As well as a thread I started myself: http://forum.pfsense.org/index.php/topic,56558.msg302461.html None of the responses were too helpful though as far as I could find as in actually getting around this. -- View this message in context: http://openbsd.7691.n7.nabble.com/PF-5-1-strange-unreachable-icmp-reply-from-firewall-tp97656p220119.html Sent from the openbsd user - misc mailing list archive at Nabble.com.