services = "{ http, https, auth, domain, nameserver }"
block all
pass out from any to any port $services
pass out on $ext_if $net_type proto { tcp, udp } from { $ext_ip, <jail_ip_list> } to any port { http, https, domain, nameserver } group { users, wheel } keep state queue web