Dazu habe ich eine Firewall Regel die entsprechende Pakete umetikettiert:
Code: Alles auswählen
/Setup/IP-Router/Firewall
> ls Rules
Name Prot. Source Destination Action LB-Policy LB-Switchover Linked Prio Firewall-Rule Stateful Src-Tag Rtg-tag
==================================---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
....
ALLOW_SMTP_FROM_VLAN600 ANY PRINTER SMTP MAILSERVER ACCEPT No No 0 Yes Yes 600 65535
....

Code: Alles auswählen
/Setup/IP-Router/Firewall
> ls Rules
Name Prot. Source Destination Action LB-Policy LB-Switchover Linked Prio Firewall-Rule Stateful Src-Tag Rtg-tag
==================================---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ALLOW-VPN-ROUTING ANY ANYHOST ANYHOST ACCEPT-VPN 0 No No 1 Yes Yes 0 0
....
/Setup/IP-Router/Firewall
> ls Actions/
Name Description
==================================----------------------------------------------------------------
ACCEPT-VPN %Lcds0 @v %A
Code: Alles auswählen
[Firewall] 2023/03/28 20:18:39,193 Devicetime: 2023/03/28 20:18:39,410
Packet matched rule ALLOW-VPN-ROUTING
DstIP: 10.1.0.75, SrcIP: 10.6.0.20, Len: 60, DSCP: CS0/BE (0x00), ECT: 0, CE: 0
Prot.: TCP (6), DstPort: 25, SrcPort: 1042, Flags: S
Seq: 3987911761, Ack: 0, Win: 16384, Len: 0
Option: Maximum segment size = 1460
Option: NOP
Option: Window scale = 0 (multiply by 1)
Option: NOP
Option: NOP
Option: 08 = 00 0c b9 4f 00 00 00 00
block-route for 10.1.0.75@600, packet rejected
