24.11.2014 Views

General Information

General Information

General Information

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

idge firewall, not in forwarded protocols as in the other case the router will not be able to<br />

receive IP packets itself, and thus will not be able to provide routing).<br />

To make bridge, drop IP, ARP and RARP packets:<br />

[admin@MikroTik] interface bridge firewall> add mac-protocol=2048 action=drop<br />

[admin@MikroTik] interface bridge firewall> add mac-protocol=2054 action=drop<br />

[admin@MikroTik] interface bridge firewall> add mac-protocol=32821 action=drop<br />

[admin@MikroTik] interface bridge firewall> print<br />

Flags: X - disabled, I - invalid<br />

0 mac-src-address=00:00:00:00:00:00 in-interface=all<br />

mac-dst-address=00:00:00:00:00:00 out-interface=all mac-protocol=2048<br />

src-address=0.0.0.0/0 dst-address=0.0.0.0/0 protocol=all action=drop<br />

1 mac-src-address=00:00:00:00:00:00 in-interface=all<br />

mac-dst-address=00:00:00:00:00:00 out-interface=all mac-protocol=2054<br />

src-address=0.0.0.0/0 dst-address=0.0.0.0/0 protocol=all action=drop<br />

2 mac-src-address=00:00:00:00:00:00 in-interface=all<br />

mac-dst-address=00:00:00:00:00:00 out-interface=all mac-protocol=32821<br />

src-address=0.0.0.0/0 dst-address=0.0.0.0/0 protocol=all action=drop<br />

[admin@MikroTik] interface bridge firewall><br />

Application Example<br />

Example<br />

Assume we want to enable bridging between two Ethernet LAN segments and have the MikroTik<br />

router be the default gateway for them:<br />

Page 184 of 568<br />

Copyright 1999-2005, MikroTik. All rights reserved. Mikrotik, RouterOS and RouterBOARD are trademarks of Mikrotikls SIA.<br />

Other trademarks and registred trademarks mentioned herein are properties of their respective owners.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!