Would be nice if the packet filter port(s) match could be inverted (!; NOT), similar to how it is for the from and to addresses.
That would allow rules like this...
block in quick on re0_vlan99 reply-to ( re0_vlan99 x.x.x.x ) inet proto {tcp udp} from {any} to {(re0_vlan99:network)} port ! { 1194 8086 22 443 }
Instead of this...
block in quick on re0_vlan99 reply-to ( re0_vlan99 x.x.x.x ) inet proto {tcp udp} from {any} to {(re0_vlan99:network)} port { 0:21 23:442 444:1193 1195:8085 8087:65535 }
That would allow rules like this...
block in quick on re0_vlan99 reply-to ( re0_vlan99 x.x.x.x ) inet proto {tcp udp} from {any} to {(re0_vlan99:network)} port ! { 1194 8086 22 443 }
Instead of this...
block in quick on re0_vlan99 reply-to ( re0_vlan99 x.x.x.x ) inet proto {tcp udp} from {any} to {(re0_vlan99:network)} port { 0:21 23:442 444:1193 1195:8085 8087:65535 }