Block PC to access local LAN on Mikrotik

Sat Mar 02, 2019 11:36 am

I have an ubuntu, insalled under vmware... I would like to set up our Mikrotik router to block this ubuntu to access local LAN.

I would like to allow access only the external internet.

I tried a lot of firewall rule, but non of work. May i ask some help about it?

Tue Mar 05, 2019 3:44 pm

Have you tried using a different IP range for the Ubuntu PC then blocking that range from accessing your local network?
Tue Mar 05, 2019 8:27 pm

The point being made is you have provided very little information to help us answer your question.
/export hide-sensitive file=yourconfig

If you have ubuntu on same subnet as the main LAN its difficult to separate out.
Much better to put that wifi on its own VLAN, or off the bridge on its own LAN etc.......
Then you are separated from the main LAN by L2 and you an apply L3 firewall filter rules (forward chain) that state
allow local traffic to ISP (lan to wan)
drop everything else (and thus vlan to LAN or LAN to VLAN traffic is not permitted).
Wed Mar 06, 2019 8:03 am

If PC is trusted and you want the firewall for good measure, then maybe iptables in ubuntu?
If PC is untrusted, then anav's suggestion is the only way. Also consider firewall input rules to protect router service ports from the untrusted computer.

