Hi to all.
I need suggestion how to configure two Mikrotik with VLANs for maximum performance and minimal Mikrotik CPU usage that should work with WiFi and local Mikrotik LAN ports, streched between two Mikrotik Router OS-es. I noticed that this can be done with different approaches so I need to know what is a proper way that should be done (what is preffered by Mikrotik).
Little intro:
I have been using Mikrotik for home purposes more than 15 years, but mostily only WiFi, routing, firewalling on simple single network. Professionaly, I am a Cisco network and VoIP engineer in a big company, so I’m preety much familiar with advanced networking, VLANs, trunking, routing and so on.
However, Mikrotik’s approach to VLANs and trunking are a bit confusing for me, as there are VLAN/PVCID/tag/untag or other related options all around different settings in Mikrotik. Not sure why are there, what differs when something is enabled/disabled or changed, as nothing seems logic to me. Tutorials for Mikrotik what I have seen are also all logic and understandable, but that tutos are regulary only covering single use case, not a complete solution. So I need your help for better understanding how to configure system in proper way. I hope that this will also be informative for other Mikrotik users who wants to learn this.
So, let’s go to a problem:
I have a two Mikrotik RouterOS-es (hAP ac^2 and RB951G-2HnD). Both should have a tree different SSIDs which sits in three different subnets. That SSIDs and subnet should be same on both Mikrotiks. So, SSID3 on Mikrotik1 shoud belongs to VLAN3, and same name SSID3 should also exists on Mikrotik2, also in VLAN3. That should be same L2/L3 network. Both Mikrotik should be inter-connected with link, on which is native (untaged) VLAN1 and tagged VLAN2 and VLAN3. That is because that link is not direct UTP cable, but goes over “dump” switch. Everything that is connected to that “dump” switch should be in untagged VLAN1.
On both Mikrotik, some ports should be configured as access ports in different VLANs: VLAN1, VLAN2 and/or VLAN3
One port on Mikrotik 1 belongs to uplink, separate network, and there is no need to be any VLAN for it as that network should not be propagated anywhere else. Mikrotik 1 should also be responsible for routing, firewalling, DHCP and so on. Mikrotik2 is actually L2 switch with WiFis, but should have possibility to configure it for same purposes as Mikrotik1 - in case of Mikrotik1 outage. I’ve attached picture for better understanding.
I have actually configured both Mikrotik for such configuration, but half of that configuration was in try and error model as some things didn’t make sense for me and still does not know what are they actually doing. I would not post for now any of configuration as that could lead someone of you to wrong direction, first I want to know what whould be a propper approach. Latter when someone post some how-to-do-it I will explain how I did it and we can discuss on that.
As I said before, my concern is on optimal and best performance configuration, not just “this is how it can work”. I can see some throughput issues in my configuration, so that is a real trigger for me to write and ask you for help.
Thanks in advance to everyone who will have any contribution to this discussion.
