Thats a cool idea. I did not really recognize the group names
before.
I could parse the output of ifconfig while the Packet Filter
is blocking everything, assign new interface group names
according to the MAC address, and finally load a new pf.conf
using group names.
Many thanx
Harri