I removed the accept rule and edited the original with "new-dst-ports=switch1-cpu" and now it works as intended.Ah, sorry - new-dst-ports=switch1-cpu is what you need. I forgot that you only needed to drop traffic from one external port to another.
It's added automatically via DHCP-Client script. You missed it.A quick read would say that you haven't added a route for you fib 'to-wan2' in your routes .. why is that
intentional or mistake ?
I'm using an external billing system which assigns the bandwidth for clients.Can you assign bandwidths via user manager and hotspot?