Hello,
I have a CRS125 that I have removed the individual ports from the switch and I'm using them as individual interfaces. I have an uplink interface, and I'm using a half dozen other interfaces as the gateway for smaller subnets. Everything in use is all publicly addressable IPs.. no internal IPs or NAT.
I have created a firewall rule which detects hosts which are connecting to ports on interfaces that they shouldn't and puts them into a blacklist which tarpits the traffic for 14 days. For instance, if someone tries to connect to my router's IP Address on port 5060, I put them in the blacklist and their traffic is tarpitted for 14 days.
This part is working....
HOWEVER, the firewall isn't blocking the traffic to ANY of the other interfaces or IP addresses. I need to block this traffic from passing through the router, not just blocking it to my router.
What am I doing incorrectly, which would allow me to use the firewall to block the traffic to all of the public subnets on the other interfaces with public subnets and IP Addresses?