Jim, considering #2 in Rulz, you can block specific traffic with a blackhole DNAT. You can allow some related traffic with a NoNAT rule above the blackhole DNAT. Cheers - Bob
↧