Load the kernel module
```
kldunload ng_ipfw
```
Replace WAN_IP with the WAN IPv4, and WAN_IF with the WAN interface.
Set the netgraph rules.
```
ngctl mkpeer ipfw: nat 60 out
ngctl name ipfw:60 nat
ngctl connect ipfw: nat: 61 in
ngctl msg nat: setaliasaddr WAN_IP
ngctl msg nat: setmode "{flags=0x100}"
```
Set the ipfw rules.
```
ipfw add 300 netgraph 61 all from any to any in via WAN_IF
ipfw add 400 netgraph 60 all from any to any out via WAN_IF
```
Set the sysctl:
```
sysctl net.inet.ip.fw.one_pass=0
```