Community discussions

MikroTik App
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 89
Joined: Wed Jan 04, 2012 5:30 pm

Bridge firewall by eth

Tue Dec 11, 2012 12:00 pm

Hi All.
I would like to isolate group of servers inside a LAN without changing ip address or using a vlans.
All should be done by a layer 2 filtering.
I would like to create a bridge of 5 interfaces.
The security model should be as follow.
1. All interfaces should have access to servers on on eth1.
2. Non of the remaining 4 interface have access to the other 4.

While doing a firewall rule with input interface as bridge I can catch the traffic.
But I would like to catch the traffic on the input interface member of the bridge with no success.

Do you think it's possible?

Thank you
User avatar
Member Candidate
Member Candidate
Posts: 138
Joined: Wed May 30, 2007 10:57 am
Location: USA

Re: Bridge firewall by eth

Tue Feb 26, 2013 3:57 am

You are looking for the firewall filter switch "in-bridge-port" and "out-bridge-port". I think you might already have figured out most of the configuration, so perhaps you just need to examine the very last line in my example below.
/interface bridge
settings set use-ip-firewall=yes
add name=bridge1
port add bridge=bridge1 interface=ether1
port add bridge=bridge1 interface=ether2
port add bridge=bridge1 interface=ether3
port add bridge=bridge1 interface=ether4
port add bridge=bridge1 interface=ether5
/ip firewall filter add chain=forward in-bridge-port=!ether1 out-bridge-port=!ether1 action=drop
- If I helped you solve your problem... I am now able to accept tax-deductible Karma donations!

Who is online

Users browsing this forum: Baidu [Spider], Google [Bot] and 27 guests