I want to block an external IP, but it seems the IP still can connect to the firewall. I have created a DNAT rule like below. Still the IP shows up in my packetfilter.log. I have created a network group which i'm using for the blocked IP, and created…