On Wed, Jan 21, 2015 at 10:48:40AM -0500, Christos Zoulas wrote: > The current implementation of groups and rules on npf is interface-specific, > and it is not finalized yet. I considered adding per interface rules, but > that introduces complexity. Perhaps I will add a flag to the daemon to > handle this, making the configuration line look like:
Wouldn't it be better per address than per interface? Martin
