Page 1 of 1

need help

Posted: Sun Nov 30, 2014 5:05 pm
by cutedrummerboy
net dia.png
here is the diagram of my current setup
all ports are master of its own
both router's ether2 have a static route to opposite side router
both router have a masquerad rule with out interface ether1



now the question is, is this setup is okay and rock solid?
is there any chance of leaking my internet to my friend or vice versa?
is there any chance of leaking my isp subnet to my friend or vice versa.

by the way,
the goal is accessing each others subnet

thanks and regards

Re: need help

Posted: Mon Dec 01, 2014 10:35 am
by cutedrummerboy
anyone? please help me.

Re: need help

Posted: Mon Dec 01, 2014 10:21 pm
by gabrielpike
It seems that what you are doing should work just fine. If you and your friend want to set up failover through each others ISPs it is possible if a gateway is added. Without a default gateway pointing at each others routers you will not be sharing internet connections.

Re: need help

Posted: Mon Dec 01, 2014 11:36 pm
by hgonzale
It looks very good. I love this design. I dont know if you have bandwidth control, priorities and something else. But this is a normal setup for that.

Re: need help

Posted: Tue Dec 02, 2014 6:40 am
by cutedrummerboy
hmm.
thanks for the replys. but you already told me the main problem. now can you help me in that case.

how can i block that internet leaking to my friend if he set his gateway as my ether2 ip address.

Re: need help

Posted: Tue Dec 02, 2014 7:51 am
by technicarl
This should do the trick:
/ip firewall filter add chain=forward action=drop in-interface=ether2 out-interface=ether1

That will add a filter rule dropping packets from your friends subnet to your isp.