Add the ossec_fwtable to /etc/pf.conf if using "firewall-drop" active response: table persist block in quick from to any block out quick from any to