steen
January 31, 2014, 9:08pm
1
Hello Folks!
I had big hopes vlan would work now, I have been waiting for several months and was happy to see 6.9 was out now.
I did make a support ticket before, back in 6.7 and was told to update to 6.8 beta something, but I did never have time over testing it.
I did reset the CRS, configured it from scratch, updated to 6.9 noticed no new firmware, but continued and configured again.
Problem remains exactly like before…
Either I do not understand how vlans work on crs or it still leaks.
If I have one trunk with 6 vlans inside and a couple of access ports attached to the trunk accordingly the documentation with examples for crs, I still see traffic from neighbour vlans and other vlans not even configured in the trunk, how come ?
I am not an expert in the matter at all, but I manage Cisco SW easely, never had a problem.
Is there anyone out there who know howto configure this device working as switch with vlans ?
Thank you in advance!
efaden
January 31, 2014, 10:14pm
2
Post your export.
Sent from my SCH-I545 using Tapatalk
steen
February 1, 2014, 7:58am
3
Here we go:
jan/02/1970 00:04:16 by RouterOS 6.9
software id = XXXX-XXXX
/interface ethernet
set [ find default-name=ether1 ] name=ether1-gateway
set [ find default-name=ether2 ] name=ether2-master-local
set [ find default-name=ether3 ] master-port=ether2-master-local name=
ether3-slave-local
set [ find default-name=ether4 ] master-port=ether2-master-local name=
ether4-slave-local
set [ find default-name=ether5 ] master-port=ether2-master-local name=
ether5-slave-local
set [ find default-name=ether6 ] master-port=ether2-master-local name=
ether6-slave-local
set [ find default-name=ether7 ] master-port=ether2-master-local name=
ether7-slave-local
set [ find default-name=ether8 ] master-port=ether2-master-local name=
ether8-slave-local
set [ find default-name=ether9 ] master-port=ether2-master-local name=
ether9-slave-local
set [ find default-name=ether10 ] master-port=ether2-master-local name=
ether10-slave-local
set [ find default-name=ether11 ] master-port=ether2-master-local name=
ether11-slave-local
set [ find default-name=ether12 ] master-port=ether2-master-local name=
ether12-slave-local
set [ find default-name=ether13 ] master-port=ether2-master-local name=
ether13-slave-local
set [ find default-name=ether14 ] master-port=ether2-master-local name=
ether14-slave-local
set [ find default-name=ether15 ] master-port=ether2-master-local name=
ether15-slave-local
set [ find default-name=ether16 ] master-port=ether2-master-local name=
ether16-slave-local
set [ find default-name=ether17 ] master-port=ether2-master-local name=
ether17-slave-local
set [ find default-name=ether18 ] master-port=ether2-master-local name=
ether18-slave-local
set [ find default-name=ether19 ] master-port=ether2-master-local name=
ether19-slave-local
set [ find default-name=ether20 ] master-port=ether2-master-local name=
ether20-slave-local
set [ find default-name=ether21 ] master-port=ether2-master-local name=
ether21-slave-local
set [ find default-name=ether22 ] master-port=ether2-master-local name=
ether22-slave-local
set [ find default-name=ether23 ] master-port=ether2-master-local name=
ether23-slave-local
set [ find default-name=ether24 ] master-port=ether2-master-local name=
ether24-slave-local
set [ find default-name=sfp1 ] name=sfp1-gateway
/interface bridge
add admin-mac=D4:CA:6D:F9:B3:74 auto-mac=no disabled=yes name=bridge-local
/ip neighbor discovery
set ether1-gateway discover=no
set sfp1-gateway discover=no
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add address-pool=default-dhcp interface=bridge-local lease-time=10m name=
default
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge-local disabled=yes interface=ether2-master-local
/interface ethernet switch egress-vlan-translation
add customer-vid=200 new-customer-vid=0 port=ether3-slave-local
add customer-vid=200 new-customer-vid=0 port=ether4-slave-local
add customer-vid=200 new-customer-vid=0 port=ether5-slave-local
add customer-vid=200 new-customer-vid=0 port=ether6-slave-local
add customer-vid=220 new-customer-vid=0 port=ether7-slave-local
add customer-vid=220 new-customer-vid=0 port=ether8-slave-local
add customer-vid=220 new-customer-vid=0 port=ether9-slave-local
add customer-vid=220 new-customer-vid=0 port=ether10-slave-local
add customer-vid=300 new-customer-vid=0 port=ether11-slave-local
add customer-vid=300 new-customer-vid=0 port=ether12-slave-local
add customer-vid=300 new-customer-vid=0 port=ether13-slave-local
add customer-vid=300 new-customer-vid=0 port=ether14-slave-local
add customer-vid=310 new-customer-vid=0 port=ether15-slave-local
add customer-vid=310 new-customer-vid=0 port=ether16-slave-local
add customer-vid=310 new-customer-vid=0 port=ether17-slave-local
add customer-vid=310 new-customer-vid=0 port=ether18-slave-local
add customer-vid=20 new-customer-vid=0 port=ether19-slave-local
add customer-vid=20 new-customer-vid=0 port=ether20-slave-local
add customer-vid=20 new-customer-vid=0 port=ether21-slave-local
add customer-vid=20 new-customer-vid=0 port=ether22-slave-local
add customer-vid=400 new-customer-vid=0 port=ether23-slave-local
add customer-vid=400 new-customer-vid=0 port=ether24-slave-local
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=200 port=ether3-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=200 port=ether4-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=200 port=ether5-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=200 port=ether6-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=220 port=ether7-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=220 port=ether8-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=220 port=ether9-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=220 port=ether10-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=300 port=ether11-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=300 port=ether12-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=300 port=ether13-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=300 port=ether14-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=310 port=ether15-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=310 port=ether16-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=310 port=ether17-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=310 port=ether18-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=20 port=ether19-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=20 port=ether20-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=20 port=ether21-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=20 port=ether22-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=400 port=ether23-slave-local sa-learning=
yes
add customer-vid=0 new-customer-vid=400 port=ether24-slave-local sa-learning=
yes
/ip address
add address=192.168.88.1/24 comment="default configuration" interface=
bridge-local network=192.168.88.0
/ip dhcp-client
add comment="default configuration" dhcp-options=hostname,clientid disabled=
no interface=ether1-gateway
add comment="default configuration" dhcp-options=hostname,clientid disabled=
no interface=sfp1-gateway
/ip dhcp-server network
add address=192.168.88.0/24 comment="default configuration" dns-server=
192.168.88.1 gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 name=router
/ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input port=22,8291 protocol=tcp
add chain=input comment="default configuration" connection-state=established
add chain=input comment="default configuration" connection-state=related
add action=drop chain=input comment="default configuration" in-interface=
ether1-gateway
add action=drop chain=input comment="default configuration" in-interface=
sfp1-gateway
add chain=forward comment="default configuration" connection-state=
established
add chain=forward comment="default configuration" connection-state=related
add action=drop chain=forward comment="default configuration"
connection-state=invalid
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" disabled=
yes out-interface=ether1-gateway
add action=masquerade chain=srcnat comment="default configuration" disabled=
yes out-interface=sfp1-gateway
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip upnp
set allow-disable-external-interface=no
/lcd interface
set ether1-gateway interface=ether1-gateway
set ether2-master-local interface=ether2-master-local
set ether3-slave-local interface=ether3-slave-local
set ether4-slave-local interface=ether4-slave-local
set ether5-slave-local interface=ether5-slave-local
set ether6-slave-local interface=ether6-slave-local
set ether7-slave-local interface=ether7-slave-local
set ether8-slave-local interface=ether8-slave-local
set ether9-slave-local interface=ether9-slave-local
set ether10-slave-local interface=ether10-slave-local
set ether11-slave-local interface=ether11-slave-local
set ether12-slave-local interface=ether12-slave-local
set ether13-slave-local interface=ether13-slave-local
set ether14-slave-local interface=ether14-slave-local
set ether15-slave-local interface=ether15-slave-local
set ether16-slave-local interface=ether16-slave-local
set ether17-slave-local interface=ether17-slave-local
set ether18-slave-local interface=ether18-slave-local
set ether19-slave-local interface=ether19-slave-local
set ether20-slave-local interface=ether20-slave-local
set ether21-slave-local interface=ether21-slave-local
set ether22-slave-local interface=ether22-slave-local
set ether23-slave-local interface=ether23-slave-local
set ether24-slave-local interface=ether24-slave-local
set sfp1-gateway interface=sfp1-gateway
/lcd interface pages
set 0 interfaces="ether1-gateway,ether2-master-local,ether3-slave-local,ether4
-slave-local,ether5-slave-local,ether6-slave-local,ether7-slave-local,ethe
r8-slave-local,ether9-slave-local,ether10-slave-local,ether11-slave-local,
ether12-slave-local"
set 1 interfaces="ether13-slave-local,ether14-slave-local,ether15-slave-local,
ether16-slave-local,ether17-slave-local,ether18-slave-local,ether19-slave-
local,ether20-slave-local,ether21-slave-local,ether22-slave-local,ether23-
slave-local,ether24-slave-local"
/tool mac-server
set [ find default=yes ] disabled=yes
add interface=ether2-master-local
add interface=ether3-slave-local
add interface=ether4-slave-local
add interface=ether5-slave-local
add interface=ether6-slave-local
add interface=ether7-slave-local
add interface=ether8-slave-local
add interface=ether9-slave-local
add interface=ether10-slave-local
add interface=ether11-slave-local
add interface=ether12-slave-local
add interface=ether13-slave-local
add interface=ether14-slave-local
add interface=ether15-slave-local
add interface=ether16-slave-local
add interface=ether17-slave-local
add interface=ether18-slave-local
add interface=ether19-slave-local
add interface=ether20-slave-local
add interface=ether21-slave-local
add interface=ether22-slave-local
add interface=ether23-slave-local
add interface=ether24-slave-local
add interface=bridge-local
/tool mac-server mac-winbox
set [ find default=yes ] disabled=yes
add interface=ether2-master-local
add interface=ether3-slave-local
add interface=ether4-slave-local
add interface=ether5-slave-local
add interface=ether6-slave-local
add interface=ether7-slave-local
add interface=ether8-slave-local
add interface=ether9-slave-local
add interface=ether10-slave-local
add interface=ether11-slave-local
add interface=ether12-slave-local
add interface=ether13-slave-local
add interface=ether14-slave-local
add interface=ether15-slave-local
add interface=ether16-slave-local
add interface=ether17-slave-local
add interface=ether18-slave-local
add interface=ether19-slave-local
add interface=ether20-slave-local
add interface=ether21-slave-local
add interface=ether22-slave-local
add interface=ether23-slave-local
add interface=ether24-slave-local
add interface=bridge-local
steen
May 24, 2014, 1:02pm
4
We finally got it working in LAB, thanks to MT support: http://forum.mikrotik.com/t/crs-documentation/71458/1 see bottom of link.