1extern = { ! 10.0.0.0/8, 10.1.2.3 } 2@0 block out log on tun1 inet from 10.1.2.3/32 to any 3@0 block out log on tun1 inet from ! 10.0.0.0/8 to any 4