изучив мануал Настроил Mikrotic
/ip route print
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S ;;; No Porno
0.0.0.0/0 192.168.121.99 1
1 A S ;;; default route
0.0.0.0/0 192.168.120.10 1
2 DS 0.0.0.0/0 192.168.200.1 1
3 A S 10.171.10.0/24 pCUB 1
4 ADS 80.244.37.55/32 192.168.120.10 0
5 ADC 192.168.120.0/24 192.168.120.2 Wan1 0
6 ADC 192.168.121.0/24 192.168.121.16 Lan1 0
7 ADC 192.168.124.0/24 192.168.124.1 Lan1 0
8 ADC 192.168.200.1/32 192.168.200.10 pCUB 0
/ip address print
192.168.120.2/24 192.168.120.0 Wan1
192.168.124.1/24 192.168.124.0 Lan1
192.168.121.16/24 192.168.121.0 Lan1
/ip firewall filter print
chain=input action=accept protocol=tcp in-interface=Wan1 dst-port=21,8291
chain=input protocol=icmp
chain=input action=accept protocol=udp
chain=input action=accept in-interface=Lan1
chain=forward action=accept out-interface=Lan1
chain=input action=accept connection-state=established
chain=forward action=accept connection-state=related
chain=output action=accept connection-state=!invalid
chain=forward action=accept src-address-list=FullInet out-interface=Wan1
/ip route print
0 0.0.0.0/0 192.168.121.99 1
1 0.0.0.0/0 192.168.120.10 1
2 DS 0.0.0.0/0 192.168.200.1 1
3 A S 10.171.10.0/24 pCUB 1
4 ADS 80.244.37.55/32 192.168.120.10 0
5 ADC 192.168.120.0/24 192.168.120.2 Wan1 0
6 ADC 192.168.121.0/24 192.168.121.16 Lan1 0
7 ADC 192.168.124.0/24 192.168.124.1 Lan1 0
Тесть На машите
# ip r g 192.168.124.211
192.168.124.211 via 192.168.121.10 dev enp3s0 src 192.168.121.99
# tcpdump -pnni enp3s0 host 192.168.124.211 and icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on enp3s0, link-type EN10MB (Ethernet), capture size 262144 bytes
10:47:30.178383 IP 192.168.121.99 > 192.168.124.211: ICMP echo request, id 29995, seq 47495, length 64
10:47:30.187391 IP 192.168.124.211 > 192.168.121.99: ICMP echo reply, id 29995, seq 47495, length 64
10:47:31.178781 IP 192.168.121.99 > 192.168.124.211: ICMP echo request, id 29995, seq 47496, length 64
10:47:31.179579 IP 192.168.124.211 > 192.168.121.99: ICMP echo reply, id 29995, seq 47496, length 64
10:47:32.178406 IP 192.168.121.99 > 192.168.124.211: ICMP echo request, id 29995, seq 47497, length 64
10:47:32.191523 IP 192.168.124.211 > 192.168.121.99: ICMP echo reply, id 29995, seq 47497, length 64
10:47:33.180721 IP 192.168.121.99 > 192.168.124.211: ICMP echo request, id 29995, seq 47498, length 64
10:47:33.181170 IP 192.168.124.211 > 192.168.121.99: ICMP echo reply, id 29995, seq 47498, length 64
но кроме пинга из 124 подсети в 121 ничего не уходит и не приходит, где сабака зарыта подскажите пожалуйста
для теста установил 2 машины на линуксе, чтобы исключить фаервол обе машины абсолютные дырки пропускают все отовсюду.