I'm having a strange PF issue that I can't seem to figure out. The basics are this... We have a 3 router configuration - 1 office router and 2 datacenter routers daisy chained together. We currently have everything up and working fine except a new subnet we just created. The new subnet works great passing through the office router to the other office subnets, and can even reach the first datacenter router. The problem starts when trying to reach the last router in the chain... Pings are successful, but any tcp traffic is refused. In troubleshooting we even enabled a "pass in all" rule to test, and traffic is still refused. We enabled "block in log (all)" and even with the pass in rule enabled, the source ip is still being logged in the block rule (and yes I know last match wins, so the pass in rule is after block in.)... Another thing is that traffic from the datacenter routers reaches the new subnet without any problems... Help please!