Configuring for 2 types of users on LAN

Hi,
On a new RB1100AHx2 what would be suggested to accomplish the following:

  1. One group (group1) of users to be able to see/access any device on the LAN (Wired and Wireless)

  2. One group (group2) of users to only have internet access and not be able to see/access other devices on the LAN. (Wired and Wireless)

Group 1 devices are static (desktops/notebooks could use MAC addresses of these devices to assign to group ?)

Group 2 devices (smart phones/notebooks are all random .. like guests)

Internet Modem ↔ RB1100AH2X ↔ PoE Switchs <-----> Wireless LAN — Group 1 (192.168.60.0) see/access all devices

Wirereless LAN --Group 2 (192.168.70.0) Internet Access ONLY

Wired LAN (192.168.50.0) would have both groups accessing it. Group 1 Users see/access all devices, Group 2 Users have Internet Access only.


I’ve added the subnets just thinking they may be needed to get this working.
Thanks for your input.

Seems like you need MAC based VLAN’s.

http://wiki.mikrotik.com/wiki/Manual:CRS_examples#MAC_Based_VLAN