OpenBSD Network ACLs for i386 – This paper discusses how to utilize a kernel patch to create local ACLs to restrict local users from using network services. It allows an administrator to deny network access for a user by restricting bind() and connect() to allowed accounts.
You can download it from the following link: https://packetstormsecurity.com/files/download/29739/openbsdacl.html
Source: https://packetstormsecurity.com/files/29739/openbsdacl.html.html