This is usually a symptom of creating state on a TCP packet other than the
initial SYN. Make sure you add "flags S/SA" to all your tcp keep state
rules. There is plenty on this in the FAQs and lists (freebsd-pf@ and
the OpenBSD pf list) for more detailed reference.
--
/"\ Best regards, | mlaier@freebsd.org
\ / Max Laier | ICQ #67774661
X http://pf4freebsd.love2party.net/ | mlaier@EFnet
/ \ ASCII Ribbon Campaign | Against HTML Mail and News