Sat Feb 18, 2023 11:48 pm
Too funny, you only put ether2 on the bridge you need the rest......
/interface bridge port
add bridge=local interface=ether1
add bridge=local interface=ether2
add bridge=local interface=ether3
add bridge=local interface=ether4
add bridge=local interface=ether5
add bridge=local interface=ether6
add bridge=local interface=ether7
Would modify your input rules slightly and fix order.......
/ip firewall filter
add action=accept chain=input comment="accept established, related" \
connection-state=established,related
add action=drop chain=input connection-state=invalid
[b]add action=accept chain=input comment="accept ICMP" protocol=icmp[/b]
add action=accept chain=input comment="Accept LAN traffic" in-interface=local
add action=drop chain=input comment="block everything else"
As for the forward chain same same.....
add action=fasttrack-connection chain=forward comment="Fasttrack not IPSEC" \
connection-mark=!ipsec connection-state=established,related hw-offload=\
yes
add action=accept chain=forward connection-state=established,related,untracked
add action=drop chain=forward comment="Drop Invalid" connection-state=invalid \
log-prefix=invalid
add action=accept chain=forward disabled=yes in-interface=local \ { enable it if you want internet traffic }
out-interface=Vodafone
add action=accept chain=forward connection-nat-state=dstnat disabled=yes { enable it if you do want port forwarding }
action=drop chain=forward comment="Drop all Else"
++++++++++++++++++++++++++++++++++++++++++++++++++
Notes:
- ICMP jumping is for the birds, not required and can get in the way of legit traffic and importantly testing.
- bogons should not be used by folks not knowing why and how they work........... which is clearly the case here....... ( copying and pasting "good ideas" from youtube should be avoided )
As for the ports seeing each other, they should by the fact they are on the same bridge and thus connected at layer 2.