My ws0 is trying to ping 10.xx.2.1 and doesnt have an arp cache. I understand what the first redirect is for since my BR is sending the ws0 to look for that ip at R3, what is the second redirect for?

I see the ping requets and responses. by the way, it isnt necessary to block out the IPs. If you are listing 10 addresses, those are private and there isnt any to know where that network is on the private LAN connected to the internet.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.