.Pp
On way out, after all checks place this rules:
.Dl "ipfw add allow record-state skip-action"
.Dl "ipfw add allow record-state defer-action"
.Dl "ipfw add nat 1"
And on way in there should be something like this: