|
||||||||
Chris Buechler wrote:
> No. Only the local subnet off of an interface is permitted outbound.
> That's automatically taken care of.
I think there should be a "SrcIp NOT <networks behind interface>"
pseudo-rule in the rule editor, just as there is a rfc-1918-block
pseudo rule. It would make the above much clearer? |