Once switch1-cpu is involved in multiple Vlans for routing purpose, each Vlan can route to WAN by its own gateway
Doing so, also inter-vlan is automatically enabled but this is unwanted.
I've got to insert a filter rule on top of my forward ones :
chain=forward action=drop in-interface=all-vlan out-interface=all-vlan
chain=forward action=accept connection-state=established,related
chain=forward action=drop connection-state=invalid
chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=pppoe-out1
chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=ether24
(first one is the only position that deny inter-vlan traffic)
However, I need some host in a single Vlan to access all hosts in the other Vlans
I've tried many rules in many order but host to inter-vlan packets are always dropped: what's the rights syntax ? where I'm wrong???
Thank you