HOW TO PREVENT SNIFFING AND SPOOFING ON RB n RouterOS ?

Hello

i have small hotspot network with soho …

my network topologi like this :

NET -------------------- RouterOS with 2.50 -----------------RB133 with 2.50 ---------- client hotspot
**********************|
**********************|
**********************|
**********************|-----------swicth ---------- client soho with 50 user


status :

  • firewall is on ( use for prevent known virus port, some ddos attack n bruteforce login on ftp n ssh port )
  • Hotspot running well with radius , using dhcp for hotspot client .
  • all network can access to the internet

the problems is :

  • i have tested sniffing and spofing my hotspot and it`s WORK !!!

solution :

  • i have tryin` add some firewall rule on RB133 and RouterOS —> search on uncle google … basic arp knowledge … and the result is dissapointed me .

  • i have no idea how to prevent this attack :sunglasses:

IF ANYONE HAVE SOME CLUE ABOUT THIS …
I`LL BE VERRY APRECIATED …

btw … thanks again for reading this …