Routing Table Policy

Here is my scenario
I have one main RB450G acting as the default gateway
port 1 is wan
port 2 is lan 192.168.88.0/24

i have another routerboard that is connected to port 2 and i assigned fixed ip 192.168.88.37 to it.
on this routerboard i created another subnet 10.10.10.0/24 and its default gateway ip is 192.168.88.1

my problem is:
a user with ip address 10.10.10.0/24 can talk to the 192.168.88.0/24 subnet and have access to all the routing table of the main gateway router.

my question is:
how can i deny this and where

your help is appreciated.

Thanks :slight_smile:

In Ip firewall.