David Young wrote:
Is this problem familiar to anyone? Is there any workaround, short of patching my kernel to track PPTP sessions? On the web, I've found out that there are two patchsets for tracking PPTP sessions in PF, so I will be trying those if no other solution shows up.
If possible, you should consider switching to L2TP.It's considered the successor to PPTP and runs over UDP, which makes it perfectly NAT-able.