Donald_William1
Feb 03, 2006Nimbostratus
Selectivly forward or drop source for IP Forwarding Virtual Server
Ok. I have a Forwarding(IP) network virtual server for a /24 network. I want to block all sources except for a select few. Here is what I have.
class dg_source {
host 10.10.10.10
host 10.10.10.11
}
rule ir_filter-source {
when CLIENT_ACCEPTED {
if {[matchclass [IP::client_addr] equals $::dg_source]} {
forward
} else {
drop
}
}
}
virtual vs-fwip_192.168.10.0-mask-24 {
destination 192.168.10.0:any
ip forward
mask 255.255.255.0
rule ir_filter-source
vlans vl_100 enable
}
Without the irule traffic forwards fine. When I apply the irule I can not connect. Please help.