I need to block some 172.16.x.x sub nets from exiting or entering the Ethernet port on a bridge link. Our upstream provider is using these block and so do we for management. We do not have a router at the demarc due to access issues. The radios have 172.16.x.x address and the one facing the rest of the world has a public too for remote access.
I have have tried dropping all packets on these subnets but nothing seems to work, and no traffic registers on the rule. How can I get the rule to work?
Erik