Hello everybody,
In our seminar I have a Mikrotik RB1100AHx2 in use. The network I have divided into 16 VLANs. All clients access the Internet via a firewall (PFSENSE). The VLANs are installed in the RB and the DHCP server as well. For maintenance reasons I often have to go into the net. For this reason I opened OPENVPN on the PFSENSE. I start at home OVPN and go via Remotedesktop on my Admin computer (172.16.5.99) (VLAN-ID5) in the net. From here I can then see the router, all switches and VLANs.
All VLANs are located in the network 172.16.XXX.0 / 24. XXX = 5 - 200 (= VLAN IDs)
Ether1 = WAN port Direction PFsense, Ether2 = LAN - VlanTrunk.
Now my questions:
1. I now want the VLANs can not see each other (no intervlan routing) but can go to the Internet.
2. I would like to continue to be able to go remote to the seminar network and to all VLANs, Switch and the RB
3. If possible, only a few rules, such as
Chain = forward action = drop in interface = allvlan out-interface = allvlan ????
I would be happy about every tip!
Greetings VlanLearner
Excuse me for my bad english (google translation)