VLAN setup, can only access MikroTik router via MAC-Telnet

Hi,

I was hoping to avoid having to post for advice but I really am stumped on this.

I have an RB850gx2, and with it, I’ve configured a network with various VLANs trunked to ether2. From there it goes to a switch (TP-Link SG108PE) and then to a Ruckus R510 access point running Unleashed firmware. Everything VLAN-related is set up properly as far as I can tell. PVID on the switch is set to the management VLAN (10) for the trunk port and the AP port. All VLANs are marked “tagged” on the trunk port. On the AP port, all are marked “tagged”, except 10, which is “untagged” so the AP gets an address on the management VLAN (by default, Ruckus APs use untagged VLAN for management traffic).

Anywho, if I connect to any of my wireless networks (each SSID has a different access VLAN), I can connect to my MikroTik router with MAC-Telnet. However, even though I get an IP on every network (through DHCP), the router has an IP on every network, there’s an allow-all firewall rule, etc. I cannot get an IP connection to the router with Winbox.

I’ve tried changing the untagged config to tagged on the switch, tried different ports, different firewall rules, and nothing seems to fix this.

Does anyone have any advice? I would really appreciate the help as this is the last hurdle before I can deploy the kit!

RSC attached.
mt-forum-issue.rsc (12.9 KB)