Previously, I had questions about VLAN and guest network. http://forum.mikrotik.com/viewtopic.php?f=7&t=77189
I did not understand how to properly isolate/separate/insulated guest network.
I decided to continue in this topic general questions about the routing and firewall ..
How to block access to the network2 (192.168.12.0/24) to other networks. To have access only to the Internet.
Code: Select all
R2---R1---R3
/ \
network1 network1
network2 network2
network2 - 192.168.12.0/24
Router 1: RouterBOARD 750UP - R1
port1 - "WAN" 192.168.10.10/24
port2 - "LAN" 192.168.11.1/24
Ports 2-5 are combined bridge1.
vlan12(bridge1) - 192.168.12.1
Router 2: RouterBOARD 951G-2HnD - R2
wlan - "Wi-fi"
port1 - "WAN" 192.168.11.20/24
port2 - "LAN"
wlan2 - VirtualAP
vlan12(bridge1) - 192.168.12.10
Port1, port2 and wlan are combined bridge1.
vlan12, wlan2 are combined bridge2.
Router 3: RouterBOARD 951G-2HnD - R3
wlan - "Wi-fi"
port1 - "WAN" 192.168.11.30/24
port2 - "LAN"
wlan2 - VirtualAP
vlan12(bridge1) - 192.168.12.20
Port1, port2 and wlan are combined bridge1.
vlan12, wlan2 are combined bridge2.