How do I kill all P2P traffic on a Masqueraded subnet?

All of the sampels show a simple firewall rule to drop traffic on all P2P, but it doesn’t seem to touch clients runningn on NAT/Masquerade.

Any ideas?

what’s the difference? the firewall p2p matcher looks at packet content and doesn’t care how your network is set up