CRS125/CRS226/etc - Help with port isolation!

Hello!


I’m trying to isolate port groups with CRS. What happen is if I try to listen the network with wireshark on a port that doesn’t have a Master port (Master port set to none) a lot of broadcast leaks to it.

I want a uplink in ether1 to isolated ports between ether2 to ether20. What I did was using ether1 as promiscuous profile override and from ether2 to ether20 isolated profile override. Thats fine with port isolation group. I’ve created another switch group with CRS125 (as far I know, just create another group with another port as master port). I’ve used ether24 as master port for ether21, ether22 and ether23.

Everything from ether1 (Broadcast, multicast, etc) is leaking to ether 21, ether22, ether23 and ether24 also! What is going on?

It’s freaking me out!

Those CRS are extremely hard to deal with!

You can set more than a Master port ?

have you tested this??

http://wiki.mikrotik.com/wiki/Manual:CRS_examples#Port_Level_Isolation

i have not tested multiple master ports but with that guide i have configured port isolation sucessfully, but that wall some time ago i dont remember well if have to tune something more

I think so

I already tried that. I want to isolate them from uplink port, the way this setup works doesn’t allow me to isolate my community from uplink ports (ether1). Still without knowing what to do.

I use multiple master ports on my RB2011.

That’s right, with other routerboards, I was able to isolate ports just doing this. It’s not working with CRS125 or 226.