Router Config
Code: Select all
# model = RB760iGS
My interface config
Code: Select all
/interface vlan
add interface=ether3 name=DMZ_VLAN vlan-id=100
add interface=ether2 name=LAN_VLAN vlan-id=10
My Firewall config
Code: Select all
/ip firewall address-list
add address=192.168.10.0/24 list=LAN_ADDRESS_VLAN
add address=192.168.100.0/24 list=DMZ_ADDRESS_VLAN
/ip firewall filter
add action=drop chain=input comment="Drop all packets from outside" in-interface=ether1
add action=accept chain=forward disabled=yes dst-address-list=DMZ_ADDRESS_VLAN src-address-list=LAN_ADDRESS_VLAN
add action=drop chain=forward disabled=yes dst-address-list=LAN_ADDRESS_VLAN log=yes src-address-list=DMZ_ADDRESS_VLAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1
My goals are quite simple
- I want full communication from my LAN_VLAN to DMZ_VLAN
- I do not want my DMZ_VLAN to access my LAN_VLAN
What am I doing wrong?