3 ms·
For TCP this is simple, only allow new connections in one direction. The better way is to separate networks by vrf, ensuring packets take the right path and go
by carlhjerpe 5y ago
For TCP this is simple, only allow new connections in one direction.
The better way is to separate networks by vrf, ensuring packets take the right path and go through your dnat rules without possible shortcuts (firewall separation works too, but then you're at the mercy of not fat-fingering any rules)