I am using some local ip ranges in my lan and to various VPNS I am connected to. Lets say they are:
10.40.0.0/16
10.41.0.0/16
10.42.0.0/16
Now it turns out that our ISP started to use one of these ranges. I hade troubles with StrongSwan going down repeatedly for days and could not figure it out.
Now to the question. Can I block off 10.0.0.0/8, 196.168.0.0/16 so that no traffic from these IPs can reach my router from wan? What is the correct way to deal with this?
Apart from the VPNs I have a standard setup with zones where LAN can reach WAN.
Firewall rules don't have any effect here. WAN to device or WAN to LAN is anyway blocked by default. The main problem here is IP conflict if the provider assigns these IPs to customers. Which is against the convention of using 100.64 for CGNAT.
So you can either notify your ISP about that, or change your addresses.
Thanks, I thought that would be against the rules. Good to have a reference on that.
ISP has fixed the problem but I dont like the idea of where a misconfiguration on WAN side would affect LAN side. I wonder if there is a solution to this.
There isn't, that is why there is the convention. 192.168.0.0/16 , 172.16.0.0/12 and 10.0.0.0/8 are private address spaces, not to be used on the internet routing tables. Since your WAN interface is part of the internet, it must either have a public IP or the ISP must use the CGNAT addresses in this case to avoid the conflicts you witnessed.
hello, can you help me please, I have configured an ip a ban range because the matchmaking always makes me play on this game server, unfortunately my game experience is catastrophic, my route trace gives me 29 hops .. here is the photo of my configuration, unfortunately it doesn't work .. what can i do? is that wrong?
First of all, do not hijack some other topic, you can open your own. Second the rule is wrong as the Destination zone should be the lan, not the Device.