I need to:
- configure sfpplus1 for the incoming fiber (WAN).
- ether2 configured for existing MGMT network (connect to another switch for remote access via infrastructure).
- ether3 configured for existing MGMT network (direct/local access to switch)
- the static IP of the switch should be 172.19.89.118/25.
- ether4-8 separate LAN ports (as bridge) that connect to the 4 routers for WAN access. Each router gets its IP via DHCP from the ISP.
- of course, ether4-8 bridge ports cannot access MGMT ports (ether2/3)
- MGMT can only talk MGMT traffic, no other ports/networks
My current configuration is below. At some point, the switch is somehow changed from switch mode to router mode; maybe this is expected based on the config or could there be a bug? And, the QuickSet info like static IP etc isn't retained after restoring a backup. Normal? Please provide a brief explanation along with any commands/directions you suggest to provide a better grasp of how to configure this properly.
Thank you!
Code: Select all
# 2024-03-13 15:31:47 by RouterOS 7.14.1
# software id = 4SEN-RUF3
#
# model = CRS310-8G+2S+
# serial number = [REMOVED]
/interface bridge
add name=MGMT_BRIDGE
add admin-mac=[REMOVED] auto-mac=no comment=defconf name=bridge
/interface list
add name=MGMT
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/interface bridge port
add bridge=bridge comment=defconf disabled=yes interface=ether1
add bridge=MGMT_BRIDGE comment=defconf interface=ether2
add bridge=MGMT_BRIDGE comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=sfp-sfpplus1
add bridge=bridge comment=defconf interface=sfp-sfpplus2
/ip neighbor discovery-settings
set discover-interface-list=none protocol=""
/interface list member
add interface=ether2 list=MGMT
add interface=ether3 list=MGMT
add disabled=yes interface=ether1 list=WAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=ether6 list=LAN
add interface=ether7 list=LAN
add interface=ether8 list=LAN
add interface=sfp-sfpplus1 list=WAN
add interface=sfp-sfpplus2 list=LAN
/ip address
add address=172.19.89.118/25 comment=defconf interface=ether2 network=\
172.19.89.0
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall filter
add action=drop chain=input in-interface=!MGMT_BRIDGE protocol=icmp
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www address=172.19.89.0/25
set ssh address=172.19.89.0/25
set api disabled=yes
set winbox address=172.19.89.0/25
set api-ssl disabled=yes
/ip ssh
set host-key-size=1024 strong-crypto=yes
#error exporting "/ipv6/nd/prefix" (timeout)
/system clock
set time-zone-name=America/Vancouver
/system identity
set name=FIBWAN
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=ca.pool.ntp.org
/system routerboard settings
set boot-os=router-os
/tool bandwidth-server
set enabled=no
/tool mac-server
set allowed-interface-list=none
/tool mac-server ping
set enabled=no