| 本帖最後由 bubblestar 於 2013-1-6 12:55 編輯 
 Thanks for the information.
 
 In case we have dual wan, I think we shall need to make an additional firewall rule after Number 4.  Shall we?
 
 Let's say,
 複製代碼[admin@MikroTik] /ip firewall filter> print
Flags: X - disabled, I - invalid, D - dynamic
0   ;;; default configuration
     chain=input action=accept protocol=icmp
1   ;;; default configuration
     chain=input action=accept connection-state=established
2   ;;; default configuration
     chain=input action=accept connection-state=related
3   ;;; default configuration
     chain=input action=drop in-interface=sfp1-gateway
4   ;;; default configuration
     chain=input action=drop in-interface=ether1-gateway
5   ;;; default configuration
     chain=input action=drop in-interface=ether2-gateway
[admin@MikroTik] 
 |