- Remove exported interfaces unused locally - Define interfaces to accept arguments - Return concrete types, not interfaces
- Accept output traffic from all default routes through VPN interface - Accept output from all default routes to outbound subnets - Accept all input traffic on ports for all default routes - Add IP rules for all default routes
FIREWALL_OUTBOUND_SUBNETS