VLANs...

Hello,

i bought rb250gs thinking it would be “ordinary L2 websmart switch”. But for some reason i am not able to set it up in way i need it to. What i need is this:

ether1: hybrid mode- tagged vlan 300 and 301, untagged(native) vlan1.
ether2: access mode- untagged vlan300.
ether3: access mode- untagged vlan301.

I expect users on port 2 and 3 wont be able to access management.

Also, it seems that ip address can have only /24 mask (why?).

And final question: can i change vlan interface to eg. vlan10 ?

thanks, marv

this is actual config.

switch seems to be doing what it wants despite the configuration, management is accessible from every port (and it doesnt really matters how is it configured), also every cca 30seconds hangs (stops responding).

this isnt what i expected :frowning:

swos ver 1.2
swos.png

Set VLAN Mode = strict for all ports and VLAN Header = add if missing for Port1.

Set password to deny management access for users.

RB250GS will not do any routing. SwOS uses a simple algorithm to ensure TCP/IP communication - it just replies to the same IP and MAC address packet came from.

Please clarify what do you mean by vlan interface in this case?

thanks for fast reply. by vlan interface i meant “vlan with ip address” but obviously, anyone can access management :open_mouth: .

so ip addres has always 24bit mask or mask is determined by class ?

Is it possible to limit management access using the acl?
It seems you could simply drop any packets with the dst ip/mac of the switch and the wrong port or vlan. This may require an entry for each vlan that is not allowed management access.

It is not clear where the acl sits in the packet flow, but it would also seem that management is port 6 of the switch chip, so this might not work as the very first acl entry is likely set at boot to forward packets with the management address to port 6.

Yes, it is possible to drop, for example, VLAN ID=100 packets that are not entering switch through port1 etc. using ACL rules.

Sorry OOT

i just want to ask how many VLANs can RB 250GS/mikrotik make…???

I’m sorry if my grammar is to bad,