This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Refuse routing for a subnet

Can I configure Astaro v6.102 to refuse to route to a particular subnet?

What I want is that for computers on the internal network that have the Astaro gateway set as their default route should still not have a valid route for a particular subnet.  Any attempt to route to that subnet should fail unless it is explicitly defined, so it has to fail if sent to the default route.

I already tried rejecting packets with that subnet destination in the packet filter, and it did not help.  A traceroute from the internal network to an address on that subnet still shows it routing to the external network.


This thread was automatically locked due to age.
Parents
  • Perhaps try removing the Static route you have in place, and use Policy routes instead... just route the traffic destined to the "bad" subnet to some non-existent private IP.. the equivalent of a "blackhole", if you will.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • Perhaps try removing the Static route you have in place, and use Policy routes instead... just route the traffic destined to the "bad" subnet to some non-existent private IP.. the equivalent of a "blackhole", if you will.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data