2/4     Since ipfw rules does not care which program is making the outbound
        access, how do I block, say all outgoing traffic except that generated
        by ssh and mozilla?
        \_ That's not really what ipfw does.  Block all outbound traffic
           destined for ports other than 80, 443 and 22.
           \_ Okay, is there a way to block based on program name in FreeBSD?
              (I heard ZoneAlarm Pro does that, but it only runs on windows?)
              \- there are some sort of hairy ways to do with with
                 fbsd involving complicated jail setups. with linux i suppose
                 you can try grsecurity. solaris-next is supposed to have much
                 finer-grain control but i'm not the best person here to talk
                 about that. what about traffic genreated by say your resolver
                 routines? --psb
                 \_ ob"we don't need no stinkin resolver routines!"
