On Wed, Jul 05, 2006 at 10:35:15AM -0700, c.s.r.c.murthy wrote: > "block all" in pf.conf is ok, but it will go away when the rules are > flushed for known/unknown reasons. I feel it is desirable to have a > kernel parameter that does default blocking when all rules are flushed.
A patch is available to do this: http://www.benzedrine.cx/pf/msg07452.html