Page 1 of 1

Filter Rules HELP

Posted: Thu Mar 13, 2014 12:44 pm
by ronybaalbaky
i have 2 router boards CCR1016-12G, each router board is assigned with a real IP , when i go to the first board and try to torch the interface with the real IP i find the IP address assigned on the second board, i tried to apply a filter rule:
/ip firewall filter
add action=drop chain=forward comment="  " dst-address=XXX.XXX.XXX.XXX src-address=0.0.0.0/0

XXX.XXX.XXX.XXX is the IP address on the second board
i can see traffic going on this rule but i can also see the "XXX.XXX.XXX.XXX" IP address on the torch
can someone please help

Re: Filter Rules HELP

Posted: Thu Mar 13, 2014 2:09 pm
by SurferTim
That is a forward rule. If you are using torch from one of the routers, and there is traffic from that router, then that would be an output rule.

Re: Filter Rules HELP

Posted: Thu Mar 13, 2014 3:26 pm
by ronybaalbaky
If i go to RB1 and torch Ether3 i can see the IP address that i putted on RB2
the following pictures will help understanding