PF作最简单的NAT (for OpenVPN)

OpenVPN创建的设备是tun0, 外网连接网卡em1

### /etc/pf.conf ###
ext_if="em1"
int_if="tun0"
internal_net="192.168.168.1/24"
external_addr="x.x.x.x"

set optimization normal
scrub in all

nat on $ext_if from $internal_net to any -> ($ext_if)

pass all