ROS 6.41 new VLANs, help...

Hi there, I’ve just bought a new RB3011 for a client, and updated it to 6.41 before I got started… and the way you do VLANs has changed :frowning:

Last time (it was an RB2011), I manually changed to hardware-based switching, set up master ports, added VLANs on each master port, added VLANs to a system-wide bridge, created new bridges with those VLANs, goodness knows what else. I never mastered hybrid ports - or indeed any trunk having anything other than the management network as its native port. Still, I was about to start again for this one.

But things have changed. So please can someone who knows advise me on the most efficient way to start achieving the VLAN/port configuration in the attached picture? An N means that VLAN should be the Native - i.e. untagged - VLAN on that port (needs that VLAN stripped on egress, and tagged on ingress), while a T is for that VLAN to appear on as part of a Trunk - i.e. tagged - on that port. (I’m sure I can manage the IPs etc.)

The layout is kind-of designed in as much as it’s mostly WAN stuff on the left 5 ports and mostly LAN stuff on the right, so on-the-same-VLAN traffic shouldn’t go over the CPU much, except that I would like access to all the VLANs on both sides of the CPU.

Many many thanks in advance…
RB3011 ports.JPG