need a rule, urgently

Hello
Good day,

hetzner sent me below abuse:

Dear Sir or Madam

We have noticed that you have been using other IPs from the same subnet in addition to the main IP mentioned in the above subject line.

As this is not permitted, we regret to inform you that your server has been deactivated.

Guidelines regarding further course of action may be found in our wiki: > http://wiki.hetzner.de/index.php/Leitfaden_bei_Serversperrung/en> .

Yours faithfully

Your Hetzner Support Team

and i added below rules in my mirktok router:

/ip firewall filter add action=drop chain=forward connection-state=invalid in-interface=ether1

This rule will drop invalid connections if your router is NAT
/ip firewall filter add action=drop chain=input connection-state=invalid in-interface=ether1

but still hetzner tell me below:

Dear Client,

the Server is still spoofing IPs.

Mit freundlichen Grüßen / Best Regards

how i can resolve it?
there is rules for drop ip spoofing in mikrotik router?

Note: i use mikrotik version 5.29

There is a tut for resolve this in iptables linux (debian or centos) how to resolve it in mikrotik: http://blackbird.si/hetzners-ban-nat-leaking-internal-traffic-on-wan-interface-and-new-year/

Thanks.

I’m not sure if it exactly helps you but you might want to look at the second post here:
http://forum.mikrotik.com/t/prevent-ip-spoofing/74146/1

Shot in the dark, but do you have proxy-arp enabled on the WAN-facing interface by chance?