Hi all.
Astaro version 7.1 (last version before 7.2, we have not updated yet).
We have problems with a bot net that is originating at a high number on machines on a service in Holland.
I want to block the whole net 85.17.0.0, so i have made a network group called "blocklist" and put 85.17.0.0/255.255.0.0 as a member in the group.
The first line in my packet filter is to block "blocklist" - any - any, which according to my logic would effeciently block that whole subnet.
However traffic to that net is not blocked at all.
So i changed the "automatic packet filter configuration" for my DNAT to manual, and put the accept rule after the block rule.
Same result.
I alsy tried to block individual adresses with the same result.
What may be a clue is that the website i want to keep "clean" is on an additional ethernet adress on the primary internet interface.
So to keep the question short: Why the h*ll cant i block traffic to an web side on the inside of the firewall that has a external adress that is not the primary adress on the interface.
My astaro reseller was as baffled as me, however we have national day in sweden today, so the reseller is having the weekend off.
Anyone stumbled upon this before?
This thread was automatically locked due to age.