By the look of the log files, the packet filter took considerable time to update the display.
I enabled the PF rule that blocks internal going to external DNS and I restarted the ASG another load of dropped packets to root DNS in t he packet filter log.
Hi kai, you win, because to change it this time also means I need to understand what I am changing and then have to change it for every up2date installation or rebuild.
I like automatic works well unless it is broken permanently and this is not a crash stop issue.