Ipfw
From FreeBSDwiki
ipfw is the kernel firewall used by FreeBSD systems. If you want to run ipfw, you need to create a firewall ruleset and the system will dynamically load the kernel module when the rc.conf statement firewall_enable="YES" is used. You do not need to compile IPFW into the FreeBSD kernel unless you want NAT function enabled. If you do plan on NAT'ing, you'll need to build a custom kernel with several ipfw-related options.
see also: Firewall, Configuring, Firewall, Monitoring