I was looking at the demo router for 2.9’s firewall rules and there is one rule in the input chain that I am not understanding and was hoping that someone is able to fill me in.
6 ;;; drop all that is not to local
chain=input dst-address-type=!local action=drop
Anyone care to take a stab at what this rule does?
It looks like any packets that are destined for router on an ip address that is not assigned to the router. What do you think?
Dan