View Single Post
Old 29th June 2014
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,975
Default

Here's a PF configuration suggestion, as follow-up. Use PF's Anchor facility.
  • Set your standard, default configuration to block the subnet.
  • Add an anchor where transient pass rules would be applied.
  • Add cron jobs to add and remove the anchor rules
On boot, access would be blocked as you desire. You could manually execute the scripts to add or remove the achor rules outside the cron(8) schedule.


See http://www.openbsd.org/faq/pf/anchors.html
Reply With Quote