Droping broadcast internal traffic

Hi, which of these conf are better for droping internal broadcast traffic except pppoe session.

1.
/ interface bridge filter
chain=forward mac-protocol=arp action=accept comment="" disabled=no
chain=forward mac-protocol=ip action=accept comment="" disabled=no
chain=forward mac-protocol=0x8863 action=accept comment="" disabled=no
chain=forward mac-protocol=0x8864 action=accept comment="" disabled=no
chain=forward action=drop comment="" disabled=no

2.
chain=forward out-interface=out-interface action=accept in-interface=in-interface mac-protocol=0x8864 disable=no
chain=forward out-interface=out-interface action=accept in-interface=in-interface mac-protocol=0x8863 disable=no
chain=input action=drop in-interface=in-interface

3.
   chain=forward action=accept mac-protocol=arp 
   chain=forward action=accept mac-protocol=ip 
   chain=forward out-interface=out-interface action=accept in-interface=in-interface mac-protocol=0x8863 
   chain=forward out-interface=out-interface action=accept in-interface=in-interface mac-protocol=0x8864 
   chain=input action=drop in-interface=in-interface

or u have something better ? :slight_smile:

Best Regards,

does anyone now ?

its simply as follows

0 chain=forward mac-protocol=0x8863 action=accept

1 chain=forward mac-protocol=0x8864 action=accept

2 chain=forward action=drop

When use chain forward action=drop all pppoe conections goes down, for chain input its working.