Hello,
i have Mikrotik 493 connected to internet via wireless card. To the 9 ethernet ports are connected 9 PC’s. Every eth. port have PPPoE concentrator. On all PC’s have set PPPoE client.
All works fine, now.
All PC’s have public address and i need set a firewall (access-lists). I need drop spoofing IP adressess. Only IP’s from range /27 can comunicate, all other drop. But don’t work it. If i select in-interface=(pppoe name of interface), then works it, but i need rules on physically eth interfaces.
0 ;;; access-list eth1
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether1
1 chain=forward action=accept out-interface=ether1
chain=forward action=drop in-interface=ether1
2 ;;; access-list eth2
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether2
3 chain=forward action=accept out-interface=ether2
chain=forward action=drop in-interface=ether2
4 ;;; access-list eth3
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether3
5 chain=forward action=accept out-interface=ether3
chain=forward action=drop in-interface=ether3
6 ;;; access-list eth4
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether4
7 chain=forward action=accept out-interface=ether4
chain=forward action=drop in-interface=ether4
8 ;;; access-list eth5
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether5
9 chain=forward action=accept out-interface=ether5
chain=forward action=drop in-interface=ether5
10 ;;; access-list eth6
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether6
11 chain=forward action=accept out-interface=ether6
chain=forward action=drop in-interface=ether6
12 ;;; access-list eth7
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether7
13 chain=forward action=accept out-interface=ether7
chain=forward action=drop in-interface=ether7
14 ;;; access-list eth8
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether8
15 chain=forward action=accept out-interface=ether8
chain=forward action=drop in-interface=ether8
16 ;;; access-list eth9
chain=forward action=accept src-address=x.y.z.160/27 in-interface=ether9
17 chain=forward action=accept out-interface=ether9
chain=forward action=drop in-interface=ether9
How i can set rule for block spoofed IP addresses ?