not necessarily only, but that would be the most common use I bet.
In general, you use it when you cannot avoid it, as in, the other
option is to not filter stateful at all since you don't see all of the
packets for the connection.
absolutely!
--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam