Did you really mean that LAN B should have no access to LAN B? Did you really mean no access B to A?
If I understand what you are trying to do, it is possible, but without your configurations, we would be guessing. Please post both configurations.
To export and paste your configuration (and I'm assuming you are using WebFig or Winbox), open a terminal window,
and type (without the quotes) "/export hide-sensitive file=any-filename-you-wish". ...
Yes, I did a mistake in my question. I've already corrected it.
As you assumed, the point is that computers from network B do not have access to network A. Of course, network B is to have access to the Internet.
I don't have this configuration implemented yet to show configs, so I do some research before implementing it.
While the rule shown, if on Mikrotik B, is mostly right. Likely not the whole story however, why config would help.
The related questions are:
- should "Mikrotik A" LAN (192.168.88.0/24) be able connect to "Mikrotik B" LAN (192.168.77.0/24)?
- should LAN clients on 192.168.77.0/24 be able to use winbox/ssh/webfig on the router(s)? – for that you may need an chain=input rule to deny 192.168.77.0/24 clients access to the router itself (e.g. if packet's dst-address=192.168.77.1 that is "input", not "forward", in firewall and have to be covered separately than than a drop forward rule)
The clients from LAN A (192.168.88.0/24) do not necessarily have access to network B (192.168.77.0/24). This means that both networks will not have access to each other.
Then the following rule will probably be enough.
ip firewall filter add chain=forward src-address=192.168.88.0/24 dst-address=192.168.77.0/24 action=drop
And previous one:
ip firewall filter add chain=forward src-address=192.168.77.0/24 dst-address=192.168.88.0/24 action=drop
The clients of LAN B should have access to routers from network A (192.168.88.1 & 192.168.88.100) through,eg Winbox and this will enable me to carry out diagnostics - then I will be able to connect to LAN B and log in to the router. I think I don't have to do anything to achieve this? I'm right?