> Or are you asking how to selectively *allow* inbound ssh traffic to
> interfaces other than en0?

Sorry--hit send too soon.

That would be something like

pass in proto tcp from <friendlies> to self port 22 flags S/SA keep state

