fujara píše:Tak pani preco by mali lietat bridgeovanou sietou broadcasty???
Cez moju siet lieta menej broadcastov ako cez vase routovane.
/ interface bridge filter
add chain=forward packet-type=broadcast action=drop
add chain=forward mac-protocol=ip action=accept
add chain=forward action=drop
A nazaver Vam este prezradim preco to tak je
/ interface bridge nat
add chain=dstnat mac-protocol=arp arp-opcode=request arp-dst-address=x.x.x.x/32 action=arp-reply to-arp-reply-mac-address=xx:xx:xx:xx:xx:xx
kde xxx je IP a MAC adresa brany. Kedy uz konecne pochopite ze bridgeoavanie je menej narocne na procesor ako routovanie? V mikrotiku to uz pochopili a preto existuje v novej trojkovej verzii use-ip-firewall=no a vidno to aj na testoch.
Tenhle filtr je zajimavy, ale co v pripade, ze si klienti berou IP z dhcp...