Hello,
i want enable fasttrack connection for my forward chain but i want add many ip addresses that not included in fast track and add a rules that drop those ips in next rules, so in this way does fast track work? and can i have better cpu performance?
this is the rules i have :
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough1 chain=forward action=fasttrack-connection src-address-list=!KVM log=no log-prefix=“”
2 chain=forward action=accept src-address-list=!KVM log=no log-prefix=“”
3 ;;; Accept ICMP
chain=input action=accept protocol=icmp dst-limit=10,5,dst-address/1m40s log=no log-prefix=“”4 ;;; Drop Unauthorized Access To Router
chain=input action=drop src-address-list=!Trusted log=no log-prefix=“”5 ;;; Drop Unauthorized Access To KVM
chain=forward action=drop src-address-list=!Trusted dst-address-list=KVM log=no log-prefix=“”6 ;;; Block Bad IPs
chain=forward action=drop src-address-list=BlockedIPs log=no log-prefix=“”7 ;;; Drop Unauthorized Access To Switches
chain=forward action=drop src-address-list=!Trusted dst-address-list=Switches log=no log-prefix=“”8 ;;; Block Traceroute To Router
chain=output action=drop protocol=icmp src-address=X.X.X.X dst-address-list=!Trusted IPs icmp-options=11:0-2559 X chain=forward action=accept in-interface=all-vlan dst-limit=2000,1000,src-address/1m log=no log-prefix=“”
10 X chain=forward action=drop in-interface=all-vlan log=no log-prefix=“”
thanks