It was decided some time ago that NPF is the One True NetBSD Firewall, and that the other, older in-tree firewalls of ipf and pf are going to be phased out due to relative lack of fixes, SMP support, and developers interested in maintaining them.

The web-based documentation in the NetBSD Guide is still extensively describing ipfilter, however.

It would be wise to start converting information from and the various examples in /usr/share/examples/npf.