Hi guys,
I am sorry to ask such a stupid question but I am really lost and have absolutely no clue why it happens....
I am running a PPTP server using address pool 192.168.3.5-10 for the pptp clients. The local address of the pptp server interface is 192.168.3.1, dns is 192.168.3.1.
There is a masquerade for source 192.168.3.0/24 to the isp uplink port so the clients can access the internet and proxy-arp on the local lan port.
Thats a pretty standard config and works fine....
What I am trying to do, is to restrict some of the addresses from the lan range 192.168.1.0 so they can't be accessed form the pptp so I created a common drop rule on the forward chain for dropping 192.168.3.0/24 source and 192.168.1.X/24 destination and placed this rule before the "accept from 192.168.3.0/24" rule.
But that doesn't trigger! Any idea why? The active connections do have 192.168.3.X address and there is no other rule for 192.168.3.0 causing the drop to be bypassed - even when placed on the top of the forward chain, it does have no impact....
Where I am missing the point? Thanks!