Hi all,
I’m working on a multiple vlan and wireless configuration on a CRS125-24G-1S-2HnD and I’m still have issues on LAN to WLAN bridge.
Intra-vlan and internet routing work correclty from any VLAN but I’m not able to reach the wired clinet from wireless and vice versa (for example LAPTOP1 to DESKTOP1 etc…).
I’m on version v6.42.1 and I’ve used the bridge configuration with hw=yes in place of the pre-v6.41 master-port. The name of the hardware bridge is LAN.
Any suggestion will be very apprecieted, thank you in advance!
–
Francesco

Below part of my configuration:
/ip address
add address=192.168.1.1/24 comment="Local IP Address" interface=BR-vlan20 network=192.168.1.0
add address=192.168.17.1/24 interface=BR-vlan17 network=192.168.17.0
add address=192.168.50.1/24 interface=BR-vlan50 network=192.168.50.0
/interface bridge
add fast-forward=no name=BR-vlan17
add fast-forward=no name=BR-vlan20
add fast-forward=no name=BR-vlan50
add comment="L2 Hardware Switch" fast-forward=no name=LAN protocol-mode=none
/interface bridge port
add bridge=LAN comment=vlan50 interface=ether2
add bridge=LAN interface=ether12
add bridge=LAN interface=ether3
add bridge=LAN interface=ether4
add bridge=LAN interface=ether5
add bridge=LAN interface=ether6
add bridge=LAN interface=ether7
add bridge=LAN interface=ether8
add bridge=LAN interface=ether9
add bridge=LAN interface=ether10
add bridge=LAN interface=ether11
add bridge=LAN interface=ether13
add bridge=LAN interface=ether15
add bridge=LAN interface=ether16
add bridge=LAN interface=ether17
add bridge=LAN interface=ether18
add bridge=LAN interface=ether19
add bridge=LAN interface=ether20
add bridge=LAN interface=ether21
add bridge=LAN interface=ether22
add bridge=LAN interface=ether23
add bridge=LAN interface=ether24
add bridge=LAN interface=sfp1
add bridge=BR-vlan20 interface=LAN-vlan20-untagged
add bridge=BR-vlan17 interface=LAN-vlan17-untagged
add bridge=BR-vlan50 interface=LAN-vlan50-untagged
add bridge=BR-vlan20 interface=WLAN-vlan20-untagged
add bridge=BR-vlan17 interface=WLAN-vlan17-untagged
add bridge=BR-vlan50 interface=WLAN-vlan50-untagged
/interface vlan
add interface=LAN name=LAN-vlan17-untagged vlan-id=17
add interface=LAN name=LAN-vlan20-untagged vlan-id=20
add interface=LAN name=LAN-vlan50-untagged vlan-id=50
add interface=WLAN-vlan17 name=WLAN-vlan17-untagged vlan-id=17
add interface=WLAN-vlan20 name=WLAN-vlan20-untagged vlan-id=20
add interface=WLAN-vlan50 name=WLAN-vlan50-untagged vlan-id=50
/interface ethernet switch
set drop-if-invalid-or-src-port-not-member-of-vlan-on-ports="ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24" forward-unknown-vlan=no
/interface ethernet switch egress-vlan-tag
add tagged-ports=sfp1,switch1-cpu vlan-id=17
add tagged-ports=sfp1,switch1-cpu vlan-id=20
add tagged-ports=sfp1,switch1-cpu vlan-id=50
add tagged-ports=sfp1,switch1-cpu
/interface ethernet switch egress-vlan-translation
add new-customer-vid=0 ports="ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24"
add new-customer-vid=0 ports=ether2
/interface ethernet switch ingress-vlan-translation
add new-customer-vid=20 ports="ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24"
add new-customer-vid=50 ports=ether2
/interface ethernet switch vlan
add ports="ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24,sfp1,switch1-cpu" vlan-id=20
add ports=ether2,sfp1,switch1-cpu vlan-id=50
add ports=sfp1,switch1-cpu vlan-id=17
add ports=sfp1,switch1-cpu vlan-id=0
/interface vlan
add interface=LAN name=LAN-vlan17-untagged vlan-id=17
add interface=LAN name=LAN-vlan20-untagged vlan-id=20
add interface=LAN name=LAN-vlan50-untagged vlan-id=50
add interface=WLAN-vlan17 name=WLAN-vlan17-untagged vlan-id=17
add interface=WLAN-vlan20 name=WLAN-vlan20-untagged vlan-id=20
add interface=WLAN-vlan50 name=WLAN-vlan50-untagged vlan-id=50
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n bridge-mode=disabled channel-width=20/40mhz-Ce disabled=no distance=indoors frequency=auto mode=ap-bridge name=WLAN-vlan50 ssid=MikroTik vlan-id=50 vlan-mode=use-tag wireless-protocol=802.11
add disabled=no keepalive-frames=disabled mac-address=66:D1:54:00:A8:47 master-interface=WLAN-vlan50 multicast-buffering=disabled name=WLAN-vlan17 ssid=Ospiti vlan-id=17 vlan-mode=use-tag wds-cost-range=0 wds-default-cost=0 wps-mode=disabled
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa-psk,wpa2-psk group-ciphers=tkip,aes-ccm mode=dynamic-keys name=AirNet_profile supplicant-identity=rt-internet unicast-ciphers=\
tkip,aes-ccm wpa-pre-shared-key=***** wpa2-pre-shared-key=*****
/interface wireless
add disabled=no keepalive-frames=disabled mac-address=66:D1:54:00:A8:48 master-interface=WLAN-vlan50 multicast-buffering=disabled name=WLAN-vlan20 security-profile=AirNet_profile ssid=AirNet vlan-id=20 vlan-mode=use-tag wds-cost-range=0 wds-default-cost=0 wps-mode=disabled
/ip pool
add name=pool-VLAN50 ranges=192.168.50.200-192.168.50.250
add name=pool-VLAN20 ranges=192.168.1.200-192.168.1.250
add name=pool-VLAN17 ranges=192.168.17.200-192.168.17.250
/ip dhcp-server
add address-pool=pool-VLAN50 disabled=no interface=BR-vlan50 name=dhcp-vlan50
add address-pool=pool-VLAN20 disabled=no interface=BR-vlan20 name=dhcp-vlan20
add address-pool=pool-VLAN17 disabled=no interface=BR-vlan17 name=dhcp-vlan17
/ip dhcp-server network
add address=192.168.1.0/24 comment=VLAN20 dns-server=192.168.1.1 domain=porcate.org gateway=192.168.1.1 netmask=24 ntp-server=192.168.1.1 wins-server=192.168.1.1
add address=192.168.17.0/24 comment=VLAN17 dns-server=192.168.17.1 domain=porcate.org gateway=192.168.17.1 wins-server=192.168.17.1
add address=192.168.50.0/24 comment=VLAN50 dns-server=192.168.50.1 domain=porcate.org gateway=192.168.50.1 wins-server=192.168.50.1



