I was given the following rule on linux ; but I'd prefer to have
something similar working on the FreeBSD router.

-p udp -m udp --dport 5060 -m string --string "Cirpack KeepAlive
Packet" --algo bm --to 65535 -j DROP

The idea is to drop packets containing a specific string on a specific
port ....

I don't think IPFW can, but who knows ...

Thank you
Jean-Yves

--
They who would give up an essential liberty for temporary security,
deserve neither liberty or security (Benjamin Franklin)