Hello all
I have a nice litte HAP AC I want to use as my home switch, my internet router, my multi SSID WiFi and my firewall device (everything ;). I have my internal home LAN (VLAN 1 - 10.0.1.0/24), DMZ (VLAN 2 - 10.0.2.0/24), IoT LAN (VLAN 3 - 10.0.3.0/24), privat LAN (VLAN 4 - 10.0.4.0/24) and a guest LAN (VLAN 5 - 10.0.5.0/24). All VLAN should have DHCP and different VLAN should be allowed on multiple, but different, interface.
This is how I would like it to be in my HAP AC:
Eth1: Routed WAN interface (not included in this question - no VLAN)
Eth2: Vlan1 - Untagged Vlan 2, 3, 4, 5 Tagged
Eth3: Vlan1 - Untagged Vlan 3, 4, 5 Tagged
Eth4: Vlan2 - Untagged Vlan 4 Tagged
Eth5: Vlan1 - Untagged
SFP: Vlan 1, 2, 3, 4, 5 Tagged
USB LTE: Routed WAN backup interface (not includet in this question - no VLAN)
As you probably understand from my VLAN names, some of the VLAN should be able to route traffic between each other and some of the VLAN should absolutly not route traffic more then out over WAN (with very hard restriction, like NTP only ![]()
If someone could help me with some sort of example configuration, I would be very happy. Like a bunch of CLI lines for VLAN, Bridges and maybe also where I should add DHCP (bridge or vlan). Also, do I get any problem if I only add my firewall rules with src/dst IP-nets and leave the interfaces empty, or is it better to also add vlan (or bridge) interfaces to the rules?
BTW, I use the lates RouterOS and I have configured different vlan trunks on switches in the past, HP, Cisco and others. But sorry to say, I just cant figure this out in RouterOS ![]()
Many thanks for any help I can get.
Best Regards
- Per Håkansson
