I am using a CRS317 as core switch with an OPNsense router. Some how I do not manage to get the CRS317 to do L3 VLAN routing.
# apr/05/2023 09:15:19 by RouterOS 7.8
# software id = R85S-8D6C
#
# model = CRS317-1G-16S+
# serial number = D7EB0DBE5D83
/interface bridge
add fast-forward=no frame-types=admit-only-vlan-tagged ingress-filtering=no \
name=BR1 priority=0x3000 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] l2mtu=1592
set [ find default-name=sfp-sfpplus1 ] l2mtu=1592
set [ find default-name=sfp-sfpplus2 ] l2mtu=1592
set [ find default-name=sfp-sfpplus3 ] l2mtu=1592
set [ find default-name=sfp-sfpplus4 ] l2mtu=1592
set [ find default-name=sfp-sfpplus5 ] l2mtu=1592
set [ find default-name=sfp-sfpplus6 ] l2mtu=1592
set [ find default-name=sfp-sfpplus7 ] l2mtu=1592
set [ find default-name=sfp-sfpplus8 ] l2mtu=1592
set [ find default-name=sfp-sfpplus9 ] l2mtu=1592
set [ find default-name=sfp-sfpplus10 ] l2mtu=1592
set [ find default-name=sfp-sfpplus11 ] l2mtu=1592
set [ find default-name=sfp-sfpplus12 ] l2mtu=1592
set [ find default-name=sfp-sfpplus13 ] l2mtu=1592
set [ find default-name=sfp-sfpplus14 ] l2mtu=1592
set [ find default-name=sfp-sfpplus15 ] l2mtu=1592
set [ find default-name=sfp-sfpplus16 ] l2mtu=1592
/interface vlan
add interface=BR1 name=GUEST_VLAN vlan-id=90
add interface=BR1 name=LAN_VLAN vlan-id=240
add interface=BR1 name=MANAGEMENT_VLAN vlan-id=99
add interface=BR1 name=SELIM_VLAN vlan-id=82
add interface=BR1 name=SERVER_VLAN vlan-id=820
add interface=BR1 name=TANJA_VLAN vlan-id=81
add interface=BR1 name=WORK_VLAN vlan-id=35
/interface ethernet switch
set 0 l3-hw-offloading=yes
/interface ethernet switch port
set 0 l3-hw-offloading=no
set 1 l3-hw-offloading=no
set 2 l3-hw-offloading=no
set 3 l3-hw-offloading=no
set 4 l3-hw-offloading=no
set 5 l3-hw-offloading=no
set 6 l3-hw-offloading=no
set 7 l3-hw-offloading=no
set 8 l3-hw-offloading=no
set 9 l3-hw-offloading=no
set 10 l3-hw-offloading=no
set 11 l3-hw-offloading=no
set 12 l3-hw-offloading=no
set 13 l3-hw-offloading=no
set 14 l3-hw-offloading=no
set 15 l3-hw-offloading=no
set 16 l3-hw-offloading=no
/interface list
add name=BASE
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/port
set 0 name=serial0
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing ospf instance
add disabled=no name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/interface bridge port
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus1
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus2
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus3
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus4
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus5
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus6
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus7
add bridge=BR1 frame-types=admit-only-vlan-tagged interface=sfp-sfpplus8
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus9 pvid=240
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus10 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus11 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus12 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus13 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus14 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus15 pvid=820
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\
sfp-sfpplus16 pvid=820
add bridge=BR1 frame-types=admit-only-vlan-tagged ingress-filtering=no \
interface=ether1
/ip neighbor discovery-settings
set discover-interface-list=BASE
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface bridge vlan
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" vlan-ids=99
add bridge=BR1 tagged="BR1,ether1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-s\
fpplus4,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7" untagged="sfp-sfpplus10,sf\
p-sfpplus11,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sf\
pplus16" vlan-ids=820
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" untagged=sfp-sfpplus9 \
vlan-ids=240
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" vlan-ids=81
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" vlan-ids=82
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" vlan-ids=35
add bridge=BR1 tagged="BR1,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4\
,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,ether1" vlan-ids=90
/interface list member
add interface=MANAGEMENT_VLAN list=BASE
/interface ovpn-server server
set auth=sha1,md5
/ip address
add address=10.8.20.17/24 interface=SERVER_VLAN network=10.8.20.0
add address=192.168.90.17/24 interface=GUEST_VLAN network=192.168.90.0
add address=192.168.8.17/24 interface=LAN_VLAN network=192.168.8.0
add address=172.16.99.17/24 interface=MANAGEMENT_VLAN network=172.16.99.0
add address=172.16.82.17/24 interface=SELIM_VLAN network=172.16.82.0
add address=172.16.81.17/24 interface=TANJA_VLAN network=172.16.81.0
add address=172.16.35.17/24 interface=WORK_VLAN network=172.16.35.0
/ip dns
set servers=172.16.99.254
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=\
established,related hw-offload=yes
add action=accept chain=forward connection-state=established,related
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=172.16.99.254 routing-table=\
main suppress-hw-offload=no
/system clock
set time-zone-name=Europe/Zurich
/system identity
set name=crs317-c1
/system ntp client
set enabled=yes
/system ntp client servers
add address=172.16.99.254
/system routerboard settings
set boot-os=router-os
/tool mac-server
set allowed-interface-list=BASE
/tool mac-server mac-winbox
set allowed-interface-list=BASE
/tool romon
set enabled=yes
I also tried the following I read in some other forum post about L3HW routing.
/interface/bridge/settings
set use-ip-firewall=yes
set use-ip-firewall-for-vlan=no
set use-ip-firewall-for-pppoe=no
set use-ip-firewall=no
Do I have to handle the port where the router is connected specially that routing is not going via the router?