thanks again for the good explanation
it seems hard with a pass-everything policy as there is much to block
should I rather do a block-everything then set pass rules ?
I have OpenBSD machines supposed to only surf the web excluding a few domains. I want to make a tight policy on each without making a change to the router's parental control settings or using some relay.conf for that.
|