Hi everyone,
stupid question I know, but somehow I either messed up my config or I didn't understand something right.
Do I need to create a block rule to disable traffic between interfaces? I thought this happens automatically, but since I have seen traffic going from one interface (LAN2) to another (LAN1) without having a rule to allow it I am kind of confused.
The default rules permit anything out from LAN. This means to all other interfaces. You need specific block rules or something with destination invert to permit Internet only but not other connected networks.
Ah, that explains it. Thanks!