Community discussions

MUM Europe 2020
 
a752412341
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 54
Joined: Sat Feb 14, 2015 8:01 pm

How do I stop MAC address access to router from Winbox on guest vlan

Fri Feb 19, 2016 12:37 am

I have a guest vlan on a different subnet from my main LAN. I have firewall rules to drop all traffic from guest to main, and any ip traffic destined for the router. Guest traffic to the Internet is allowed. This works fine.

I can still access the router using Winbox from the guest vlan using the Mac address. How do I stop this?
Thanks!
 
kiaunel
Member Candidate
Member Candidate
Posts: 211
Joined: Mon Jul 21, 2014 7:59 pm
Location: Romania

Re: How do I stop MAC address access to router from Winbox on guest vlan

Fri Feb 19, 2016 11:15 am

I think you block traffic in forward chain. When you access router in winbox the packets are in input chain, they are destinated for the router itself. Others, for others devices are passing the router , this means forward. This is for ip. About mac access i don`t know if you can realy block... maybe in bridge firewall ... never tryed.
Later edit:
I`ve made an test on my device, Disabled one interface in tools--mac telnet --- winbox. Winbox see the mac of the microtik but can not connect by mac... only by ip. Try this if it helps
 
Sob
Forum Guru
Forum Guru
Posts: 4887
Joined: Mon Apr 20, 2009 9:11 pm

Re: How do I stop MAC address access to router from Winbox on guest vlan

Fri Feb 19, 2016 7:57 pm

Check under /tool mac-server.
People who quote full posts should be spanked with ethernet cable. Some exceptions for multi-topic threads may apply.
 
a752412341
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 54
Joined: Sat Feb 14, 2015 8:01 pm

Re: How do I stop MAC address access to router from Winbox on guest vlan

Sat Feb 20, 2016 12:18 am

Thanks both for the help. Yes I changed the mac-telnet server to be enabled on only the LAN bridge.

/tool mac-server
add disabled=no interface=bridgeLAN
disable numbers=0

/tool mac-server mac-winbox
add disabled=no interface=bridgeLAN
disable numbers=0

Solved. thanks.

Who is online

Users browsing this forum: No registered users and 40 guests