bogon_unreach.conf 951 B

123456789101112131415161718192021222324
  1. # Add unreachable routes for any prefix we don't want to route to
  2. # the internet.
  3. protocol static bogon_unreach {
  4. {%- if proto == 'v4' %}
  5. # RFC1918, RFC 6598, APIPA, TEST nets, and stuff
  6. route 0.0.0.0/8 unreachable; # Host-Subnet
  7. route 10.0.0.0/8 unreachable; # RFC 1918
  8. route 100.64.0.0/10 unreachable; # RFC 6598
  9. route 169.254.0.0/16 unreachable; # APIPA
  10. route 172.16.0.0/12 unreachable; # RFC 1918
  11. route 192.0.0.0/24 unreachable; # IANA RESERVED
  12. route 192.0.2.0/24 unreachable; # TEST-NET-1
  13. route 192.168.0.0/16 unreachable; # RFC 1918
  14. route 198.18.0.0/15 unreachable; # BENCHMARK
  15. route 198.51.100.0/24 unreachable; # TEST-NET-2
  16. route 203.0.113.0/24 unreachable; # TEST-NET-3
  17. route 224.0.0.0/3 unreachable; # MCast + Class E
  18. {%- else %}
  19. route ::/96 unreachable; # RFC 4291
  20. route 2001:db8::/32 unreachable; # Documentation
  21. route fec0::/10 unreachable; # Site Local
  22. route fc00::/7 unreachable; # ULA
  23. {%- endif %}
  24. }