Community discussions

MikroTik App
 
DavidTSanchez
just joined
Topic Author
Posts: 4
Joined: Fri Jun 25, 2021 8:01 pm

What configuration is best in vlan-filtering??

Wed Mar 06, 2024 8:55 pm

Hi
I would like read your opinion about following configuration
Which configuration (cfg) is correct?

Both cfg works but i read on mikrotik wiki "network cfg can works but it's not always the optimal cfg"

In the first cfg i dont use vlan-filering, it's just a vlan for each physical interface and then i put them inside a bridge

The advantage is i dont put the physical interfaces on a bridge, so a broadcast traffic can't pass through the router and other layer 2 services through vlan1 neither. Only the vlan 90 can pass

The second cfg i put the physical interfaces on a bridge but i used vlan-filtering. Only vlan 90 can pass through the router and i set the "admit only vlan tagged" on the bridge port's

So i would like read your opinions. Thanks
Both.jpeg
You do not have the required permissions to view the files attached to this post.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11647
Joined: Thu Mar 03, 2016 10:23 pm

Re: What configuration is best in vlan-filtering??

Wed Mar 06, 2024 9:58 pm

The correct configuration is whichever produces wanted results.

The (resource utilization wise) optimal configuration for most MT device models is the one with single bridge with vlan-filtering enabled. You didn't mention the model you're using so it may not be optimal after all.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19409
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: What configuration is best in vlan-filtering??

Wed Mar 06, 2024 10:50 pm

I dont understand the diagrams but my short answer is YES.
 
RhoAius
newbie
Posts: 31
Joined: Fri Jul 12, 2019 10:47 pm

Re: What configuration is best in vlan-filtering??  [SOLVED]

Wed Mar 06, 2024 11:32 pm

But broadcast traffic from the vlan 90 is still going through for both configurations.

All in all I would go with option 2 as it scales better if the need arises for another vlan, and it will because you are already tagging vlan 90.
Also to eliminate the potential vlan 1 rogue broadcast properly configure your ports in the bridge
  • enable vlan filtering on the bridge
  • set correct pvid and frame type for the ports in the bridge and also enable ingress filtering here
  • another reason to use the second configuration style is that depending on the mkt hardware you have a chance of hw vlan
    doing the first option almost guarantees everything happens on the cpu of the device.

Who is online

Users browsing this forum: aoakeley, Bing [Bot], panzermaster18 and 40 guests