After doing a bit of digging I see that SYN packets are the first in creating a TCP handshake - although in this case it must be initiated by the web page loaded in my browser.

(This also assumes that I'm reading pfSense's logs right, and TCP:S doesn't include a SYN ACK?)

If that's the case, I think that allowing all SYN packets from my lan to the host site's network should be reasonably secure.


If anyone knows otherwise please let me know!