When packets go out ether2, they need to take on ether2's pubic IP. 1. IP > Firewall > NAT, add masquerade rule for packets going out ether2. Same for ether1 (it probably exists already) At this point packets will still go out Ether1. So setup Mangle rules and routing. The mangle rule will mark pac...