allow gre from any to any via EXT_IF allow tcp from any to EXT_ADDR pptp in recv EXT_IF allow tcp from EXT_ADDR pptp to any out xmit EXT_IF