Hi.
I want to block internet access to a specific range of IP addresses. Here is my Network Settings:
LAN Range: 192.168.48.0/24
DHCP serves dynamic IP's in this range: 192.168.48.100-192.168.48.254
I want to block internet access to this range: 192.168.48.150-192.168.48.200
The thing is, I dont want to block the whole subnet, just part of it.
How can I do this? is it possible via luci?
if not, is possible by editing uci config file "/etc/config/firewall" or I should use pure custom iptables commands?
BTW, this is my /etc/config/firewall:
config defaults
option syn_flood '1'
option input 'DROP'
option output 'DROP'
option forward 'DROP'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
option output 'ACCEPT'
option masq '1'
option mtu_fix '1'
option input 'DROP'
option forward 'DROP'
config forwarding
option src 'lan'
option dest 'wan'
config include
option path '/etc/firewall.user'
(Last edited by euphoria360 on 1 May 2016, 12:45)