Just building this out but got stuck when i put on vlan filtering on the bridge. Did some searching but never found a complete answer.
There is no IP on MGMT as I use a direct connect ethernet cable to the MGMT/BOOT port and connect via MAC.
I could not find a similar config.
I have HW offload turned on in the winbox interface but it does not seem to show up in the config.
Been a while since i did a bunch of command line stuff.
So removing the vlan filtering using an RJ45 serial console cable was interesting ![]()
Just trying to get the admin port to work when i turn on vlan filtering.
Thanks
/interface bridge
add admin-mac=18:FD:74:3F:15:B7 auto-mac=no comment=defconf name=bridge port-cost-mode=short
/interface vlan
add interface=bridge name=VLAN7-VVID vlan-id=7
add interface=bridge name=VLAN8-VPLX vlan-id=8
add interface=bridge name=VLAN17-VIOT vlan-id=17
add interface=bridge name=VLAN20-VCST vlan-id=20
add interface=bridge name=VLAN21-VSEC vlan-id=21
add interface=bridge name=VLAN22-VRK vlan-id=22
add interface=bridge name=VLAN23-VPRN vlan-id=23
add interface=bridge name=VLAN24-VMSC vlan-id=24
add interface=bridge name=VLAN99-MGMT vlan-id=99
add interface=bridge name=VLAN111-CORE vlan-id=111
add interface=bridge name=VTRUNK1111-QSFP1-4 vlan-id=1111
add interface=bridge name=VTRUNK1112-QSFP15-8 vlan-id=1112
/interface list
add name=LAN
add name=MGMT
add name=VTRUNK1
add name=VLAN111
add name=VLAN7
add name=VLAN8
add name=VLAN17
add name=VLAN20
add name=VLAN21
add name=VLAN22
add name=VLAN23
add name=VLAN24
add name=VLAN99
add name=VTRUNK2
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/ip ipsec proposal
set [ find default=yes ] disabled=yes
/port
set 0 name=serial0
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing ospf instance
add disabled=no name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/interface bridge filter
add action=drop chain=input dst-port=68 in-interface=!ether1 ip-protocol=udp mac-protocol=ip
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether1 internal-path-cost=10 path-cost=10 pvid=99
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus1-1 internal-path-cost=10 path-cost=10 pvid=1111
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus1-2 internal-path-cost=10 path-cost=10 pvid=1111
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus1-3 internal-path-cost=10 path-cost=10 pvid=1111
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus1-4 internal-path-cost=10 path-cost=10 pvid=1111
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus2-1 internal-path-cost=10 path-cost=10 pvid=1112
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus2-2 internal-path-cost=10 path-cost=10 pvid=1112
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus2-3 internal-path-cost=10 path-cost=10 pvid=1112
add bridge=bridge comment=defconf frame-types=admit-only-vlan-tagged interface=qsfpplus2-4 internal-path-cost=10 path-cost=10 pvid=1112
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 internal-path-cost=10 path-cost=10 pvid=111
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 internal-path-cost=10 path-cost=10 pvid=8
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 internal-path-cost=10 path-cost=10 pvid=7
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 internal-path-cost=10 path-cost=10 pvid=17
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 internal-path-cost=10 path-cost=10 pvid=17
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 internal-path-cost=10 path-cost=10 pvid=17
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 internal-path-cost=10 path-cost=10 pvid=20
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 internal-path-cost=10 path-cost=10 pvid=21
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 internal-path-cost=10 path-cost=10 pvid=22
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus23 internal-path-cost=10 path-cost=10 pvid=23
add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus24 internal-path-cost=10 path-cost=10 pvid=24
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set accept-redirects=no accept-router-advertisements=no disable-ipv6=yes forward=no max-neighbor-entries=8192
/interface bridge vlan
add bridge=bridge tagged=VLAN111-CORE vlan-ids=111
add bridge=bridge tagged=VLAN7-VVID vlan-ids=7
add bridge=bridge tagged=VLAN8-VPLX vlan-ids=8
add bridge=bridge tagged=VLAN17-VIOT vlan-ids=17
add bridge=bridge tagged=VLAN20-VCST vlan-ids=20
add bridge=bridge tagged=VLAN21-VSEC vlan-ids=21
add bridge=bridge tagged=VLAN22-VRK vlan-ids=22
/interface list member
add interface=sfp-sfpplus1 list=LAN
add interface=sfp-sfpplus2 list=LAN
add interface=sfp-sfpplus3 list=LAN
add interface=sfp-sfpplus4 list=LAN
add interface=sfp-sfpplus5 list=LAN
add interface=sfp-sfpplus6 list=LAN
add interface=sfp-sfpplus7 list=LAN
add interface=sfp-sfpplus8 list=LAN
add interface=sfp-sfpplus9 list=LAN
add interface=sfp-sfpplus10 list=LAN
add interface=sfp-sfpplus11 list=LAN
add interface=sfp-sfpplus12 list=LAN
add interface=sfp-sfpplus14 list=LAN
add interface=sfp-sfpplus15 list=LAN
add interface=sfp-sfpplus16 list=LAN
add interface=sfp-sfpplus17 list=LAN
add interface=sfp-sfpplus18 list=LAN
add interface=sfp-sfpplus19 list=LAN
add interface=sfp-sfpplus20 list=LAN
add interface=sfp-sfpplus21 list=LAN
add interface=sfp-sfpplus22 list=LAN
add interface=sfp-sfpplus23 list=LAN
add interface=sfp-sfpplus24 list=LAN
add interface=qsfpplus1-1 list=VTRUNK1
add interface=qsfpplus1-2 list=VTRUNK1
add interface=qsfpplus1-3 list=VTRUNK1
add interface=qsfpplus1-4 list=VTRUNK1
add interface=qsfpplus2-1 list=VTRUNK2
add interface=qsfpplus2-2 list=VTRUNK2
add interface=qsfpplus2-3 list=VTRUNK2
add interface=qsfpplus2-4 list=VTRUNK2
add interface=ether1 list=MGMT
/interface ovpn-server server
set auth=sha1,md5
/ip address
add address=10.111.1.0/24 interface=VTRUNK1111-QSFP1-4 network=10.111.1.0
add address=10.7.0.0/24 interface=VLAN7-VVID network=10.7.0.0
add address=10.8.0.0/24 interface=VLAN8-VPLX network=10.8.0.0
add address=10.17.0.0/24 interface=VLAN17-VIOT network=10.17.0.0
add address=10.20.0.0/24 interface=VLAN20-VCST network=10.20.0.0
add address=10.21.0.0/24 interface=VLAN21-VSEC network=10.21.0.0
add address=10.22.0.0/24 interface=VLAN22-VRK network=10.22.0.0
add address=10.23.0.0/24 interface=VLAN23-VPRN network=10.23.0.0
add address=10.24.0.0/24 interface=VLAN24-VMSC network=10.24.0.0
add address=10.99.0.0/24 interface=VLAN99-MGMT network=10.99.0.0
add address=10.112.1.0/24 interface=VTRUNK1112-QSFP15-8 network=10.112.1.0
add address=10.1.1.0/24 interface=VLAN111-CORE network=10.1.1.0
/ip arp
add address=10.1.0.100 interface=bridge mac-address=54:E1:AD:E6:04:9C
/ip dhcp-client
add disabled=yes interface=bridge
/ip dhcp-relay
add dhcp-server=10.1.1.1 disabled=no interface=VLAN111-CORE local-address=10.1.1.3 name=VLAN111-CORE-Relay
add dhcp-server=10.24.0.1 disabled=no interface=VLAN24-VMSC local-address=19.24.0.3 name=VLAN24-MSC-relay
add dhcp-server=10.23.0.1 disabled=no interface=VLAN23-VPRN local-address=10.23.0.3 name=VLAN23-VPRN-relay
add dhcp-server=10.22.0.1 disabled=no interface=VLAN22-VRK local-address=10.22.0.3 name=VLAN22-VRK-relay
add dhcp-server=10.21.0.1 disabled=no interface=VLAN21-VSEC local-address=10.21.0.3 name=VLAN21-VSEC-relay
add dhcp-server=10.20.0.1 disabled=no interface=VLAN20-VCST local-address=10.20.0.3 name=VLAN20-VCST-relay
add dhcp-server=10.17.0.1 disabled=no interface=VLAN17-VIOT local-address=10.17.0.3 name=VLAN17-VIOT-relay
add dhcp-server=10.8.0.1 disabled=no interface=VLAN8-VPLX local-address=10.8.0.3 name=VLAN8-PLX-Relay
add dhcp-server=10.7.0.1 disabled=no interface=VLAN7-VVID local-address=10.7.0.3 name=VLAN7-VVID-relay
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
/ip hotspot service-port
set ftp disabled=yes
/ip ipsec policy
set 0 disabled=yes
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip smb
set allow-guests=no
/routing bfd configuration
add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/system clock
set time-zone-name=America/New_York
/system identity
set name=CORE
/system note
set show-at-login=no
/system routerboard settings
set boot-os=router-os