#RouterOS v7##Copy and paste these on both Edge and BNG routers#/ip routeadd blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=0.0.0.0/8add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=172.16.0.0/12add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=192.168.0.0/16add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=10.0.0.0/8add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=169.254.0.0/16add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=127.0.0.0/8add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=224.0.0.0/4add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=198.18.0.0/15add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=192.0.0.0/24add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=192.0.2.0/24add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=198.51.100.0/24add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=203.0.113.0/24add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=100.64.0.0/10add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=240.0.0.0/4add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=192.88.99.0/24add blackhole comment="Blackhole route for RFC6890 (limited broadcast)" disabled=no dst-address=255.255.255.255/32#RouterOS v7##Copy and paste these on both Edge and BNG routers#/ipv6 routeadd blackhole comment="Blackhole route for RFC6890" disabled=no dst-address=::1/128add blackhole comment="Blackhole route for RFC6890" disabled=no dst-address=::/128add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=64:ff9b::/96add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=::ffff:0:0/96add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=100::/64add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2001::/23add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2001::/32add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2001:2::/48add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2001:db8::/32add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2001:10::/28add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=2002::/16add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=fc00::/7add blackhole comment="Blackhole route for RFC6890 (aggregated)" disabled=no dst-address=fe80::/10
You can blackhole route on opnsense as well - nexthop would be the Null device.
Ah! They are static routes instead of firewall rules :-), never used them before. I will play around with them also to see how this works. thanks. P.S. is there any downside of using this / black-holing?P.S.S. if you disable the loopback addresses, why have you configured them?