Hello masters of Mikrotik,
please i would like to be adviced.
Having two networks 192.168.2.0/24 and 192.168.20.0/24.
I would like to have those network isolated as i run some virtuals on 20.0/24 network.
BUT in some case i need to access from 192.168.2.17 to 192.168.20.200:8006.
There are my rules:
11 chain=forward action=accept protocol=tcp dst-address=192.168.20.200
dst-port=8006 log=yes log-prefix=""
12 chain=forward action=drop src-address=192.168.2.0/24
dst-address=192.168.20.0/24 log=yes log-prefix=""
13 chain=forward action=drop src-address=192.168.20.0/24
dst-address=192.168.2.0/24 log=yes log-prefix=""
But its not working. I suppose the reason is that when 20.200 is trying to reply to "initiaiton" port its being dropped. What is the best practise to keep this working?
Thanks!