Hello,
This is my goal :
- VLAN-40 access to VLAN-41 = accept
- VLAN-40 access to VLAN-50 = drop
- VLAN-40 access to VLAN-51 = drop
- VLAN-40 access to internet = accept
and
- VLAN-50 access to VLAN-51 = accept
- VLAN-50 access to VLAN-40 = drop
- VLAN-50 access to VLAN-41 = drop
- VLAN-50 access to internet = accept
when i add two line to go to internet, all VLAN-40 talk with VLAN-50 and vise-ver-sa
/ip firewall address-list
add address=0.0.0.0/8 list=not_in_internet
add address=10.0.0.0/8 list=not_in_internet
add address=127.0.0.0/8 list=not_in_internet
add address=169.254.0.0/16 list=not_in_internet
add address=192.0.2.0/24 list=not_in_internet
add address=192.88.99.0/24 list=not_in_internet
add address=198.18.0.0/15 list=not_in_internet
add address=198.51.100.0/24 list=not_in_internet
add address=203.0.113.0/24 list=not_in_internet
add address=224.0.0.0/4 list=not_in_internet
add address=192.168.40.0/24 list=vlan-40-intern-list
add address=192.168.50.0/24 list=vlan-50-direction-list
add address=192.168.41.0/24 list=vlan-41-prod-list
add address=192.168.51.0/24 list=vlan-51-prod-list
/ip firewall filter
add chain=forward dst-address-list=not_in_internet action=drop comment="protection"
add chain=input connection-state=invalid action=drop comment="protection"
add chain=input connection-state=established,related action=accept comment="protection"
add chain=forward connection-state=invalid protocol=tcp action=drop comment="protection"
add chain=forward connection-state=established,related action=accept comment="protection"
add chain=input in-interface=bridge-trunk src-address-list=vlan-250-wifi-guest-list dst-port=21,22,23,8291 protocol=tcp action=drop comment="protection"
add chain=forward src-address-list=vlan-40-intern-list dst-address-list=vlan-41-prod-list action=accept comment="VLAN-40-to-VLAN-41"
add chain=forward src-address-list=vlan-50-direction-list dst-address-list=vlan-51-prod-list action=accept comment="VLAN-50-to-VLAN-51"
####problem####
add chain=forward src-address-list=vlan-40-intern-list dst-address=0.0.0.0/0 action=accept comment="VLAN-40-INTERNE-to-internet"
add chain=forward src-address-list=vlan-50-direction-list dst-address=0.0.0.0/0 action=accept comment="VLAN-50-DIRECTION-to-internet"
####problem####
add chain=input action=drop comment="DENY-ALL"
add chain=forward action=drop comment="DENY-ALL"

mikrotik-bridge-MultiWAN.pdf (140 KB)
Could you please tell me if any other solution to do this :
- VLAN-40 access to VLAN-41 = accept
- VLAN-40 access to VLAN-50 = drop
- VLAN-40 access to VLAN-51 = drop
- VLAN-40 access to internet = accept
and
- VLAN-50 access to VLAN-51 = accept
- VLAN-50 access to VLAN-40 = drop
- VLAN-50 access to VLAN-41 = drop
- VLAN-50 access to internet = accept
Many thanks per advance for your great help
Best regards:
p.s: if you want to see my mangle configuration, you can check this http://forum.mikrotik.com/t/problem-high-ping-latency-multiwan/143312/1