Default forwarding x security

Hi all,

I dont know if the topic title is right, but…

I have the configuration below

MK1------WDS 5.8 link-------MK2—AP 2.4—customers

MK1 = mikrotik 1 in bridge mode
MK2 = mikrotik 2 in bridge mode

I disabled the default forwanding in the AP… This is OK… a customer can’t see another one in the same AP. But I’ve a doubt:

If I get access to the AP with my FreeBSD machine and run a tcpdump on my wireless interface I can see the traffic from the INTERNET to my CUSTOMERS… (never from my customers to the internet). I think that the tcpdump get the traffic from the interface that are doing the PTP with MK1 (because it’s in bridge mode).

How can I solve this??? I want that the tcpdump don’t get any traffic that don’t allow to de customer.

s

Fabricio