how to isolate vlan
Posted: Fri Apr 13, 2012 3:38 pm
Hi,
I'm newbe in mikrotik. Connected 2 computer on HP procurve 2626 switch with configured vlans.
One pc belongs to vlan2 another to vlan4. Both have access to internet and both see each other. Please advice how to isolate computers?
My config:
HP port 2 vlan2 untagged
HP port 4 vlan4 untagged
HP port26 vlan2,4 tagged connected to mikrotik ether2
ether1 connected to internet.
[admin@MikroTik] > interface print
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE MTU L2MTU MAX-L2MTU
0 R ether1 ether 1500
1 R ether2 ether 1500
2 R vlan2 vlan 1500
3 R vlan4 vlan 1500
[admin@MikroTik] > ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 192.168.3.171/24 192.168.3.0 ether1
1 192.168.2.1/24 192.168.2.0 vlan2
2 192.168.4.1/24 192.168.4.0 vlan4
[admin@MikroTik] > ip route print
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S 0.0.0.0/0 192.168.3.254 1
1 ADC 192.168.2.0/24 192.168.2.1 vlan2 0
2 ADC 192.168.3.0/24 192.168.3.171 ether1 0
3 ADC 192.168.4.0/24 192.168.4.1 vlan4 0
[admin@MikroTik] > ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=src-nat to-addresses=192.168.3.171
src-address=192.168.2.0/24
1 chain=srcnat action=src-nat to-addresses=192.168.3.171
src-address=192.168.4.0/24
I'm newbe in mikrotik. Connected 2 computer on HP procurve 2626 switch with configured vlans.
One pc belongs to vlan2 another to vlan4. Both have access to internet and both see each other. Please advice how to isolate computers?
My config:
HP port 2 vlan2 untagged
HP port 4 vlan4 untagged
HP port26 vlan2,4 tagged connected to mikrotik ether2
ether1 connected to internet.
[admin@MikroTik] > interface print
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE MTU L2MTU MAX-L2MTU
0 R ether1 ether 1500
1 R ether2 ether 1500
2 R vlan2 vlan 1500
3 R vlan4 vlan 1500
[admin@MikroTik] > ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 192.168.3.171/24 192.168.3.0 ether1
1 192.168.2.1/24 192.168.2.0 vlan2
2 192.168.4.1/24 192.168.4.0 vlan4
[admin@MikroTik] > ip route print
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S 0.0.0.0/0 192.168.3.254 1
1 ADC 192.168.2.0/24 192.168.2.1 vlan2 0
2 ADC 192.168.3.0/24 192.168.3.171 ether1 0
3 ADC 192.168.4.0/24 192.168.4.1 vlan4 0
[admin@MikroTik] > ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=src-nat to-addresses=192.168.3.171
src-address=192.168.2.0/24
1 chain=srcnat action=src-nat to-addresses=192.168.3.171
src-address=192.168.4.0/24