I'm playing around with the "Use IP firewall for VLAN" and can't really understand how to give it a cleaner look. Here's the fairly easy test setup:
* single bridge with 2 access ports
* both vlan and bridge belong to the same interface list Test
Code: Select all
# jan/01/2002 02:10:36 by RouterOS 6.45.8
/interface bridge
add fast-forward=no name=bridge1 pvid=7 vlan-filtering=yes
/interface vlan add interface=bridge1 name=vlan7 vlan-id=7
/interface list add name=Test
/ip pool add name=dhcp_pool1 ranges=7.7.7.10-7.7.7.25
/ip dhcp-server add address-pool=dhcp_pool1 disabled=no interface=vlan7 name=dhcp
/interface bridge port
add bridge=bridge1 hw=no interface=ether2 pvid=7
add bridge=bridge1 hw=no interface=ether10 pvid=7
/interface bridge settings
set allow-fast-path=no use-ip-firewall=yes use-ip-firewall-for-vlan=yes
/ip firewall connection tracking set enabled=yes
/interface bridge vlan
add bridge=bridge1 tagged=bridge1 untagged=ether2,ether10 vlan-ids=7
/interface list member
add interface=vlan7 list=Test
add interface=bridge1 list=Test
/ip address
add address=7.7.7.0/24 interface=vlan7 network=7.7.7.0
/ip dhcp-server network
add address=7.7.7.0/24 gateway=7.7.7.1
/ip firewall filter
add action=accept chain=forward in-interface-list=Test protocol=icmp
add action=accept chain=forward protocol=icmp src-address=7.7.7.0/24
add action=drop chain=forward log=yes log-prefix=P protocol=icmp
Next test I remove the Bridge from the interface list, but leave vlan in the list. Now it's the 2nd rule with ip addresses counting packets.
Does this mean that interface lists don't work with vlans? Does it work based on IP addresses only? But why then such a difference in I remove Bridge from the list.