The Power Of Tags

tag packets incoming, block or pass outgoing based on tags

eg in a net with several NATing access points, you tag incoming traffic

wifi = "{,,, }"
pass in on $int_if from $wifi to $wifi_allowed port \
     $wifi_ports tag wifigood
pass out on $ext_if tagged wifigood

Then pass or block based on the tag

NOTE: tags are sticky and could be overwritten - all matching tag rules tag, last tag stays