keep-state
Upon a match, the firewall will create a dynamic rule, whose
default behaviour is to match bidirectional traffic between
source and destination IP/port using the same protocol. The rule
has a limited lifetime (controlled by a set of sysctl(8) vari-
ables), and the lifetime is refreshed every time a matching
packet is found.