os x
/etc/pf.conf
--
scrub-anchor "com.apple/*"
nat-anchor "com.apple/*"
rdr-anchor "com.apple/*"
dummynet-anchor "com.apple/*"
anchor "com.apple/*"
load anchor "com.apple" from "/etc/pf.anchors/com.apple"
wifi=en1
#vpn=utun0
vpn=tap0
block all
set skip on lo # allow local traffic
pass on $wifi proto tcp to <vpn ip> port <vpn port>
pass on $wifi proto tcp to 192.168.1.0/24
pass on $vpn # allow everything else through the VPN (tun interface)