CRS125-24G-1S
RouterOS v6.41
FW type = ar9344
FW = 3.33
i currently have a working setup, which i've backed up so i always have something to fall back to. it currently runs a cable modem into eth1, which i used a quick set for basic router usage. it made a bridge which includes eth2-24 and sfp+. as i understand it, this is taxing on the cpu, and doesnt allow my devices to file transfer across the LAN as quick as they should since this device is mostly a switch with basic routing features built in. the front panel allocates the rj45 jacks into 3 sections of 8, i am using these sections to visually separate my eth jacks into three sections: a basic routing group of 8, a VLAN with internet access, and another VLAN which only has access to other VLANS and devices behind the gateway, but NO INTERNET ACCESS. is this achievable?
the following is what i am hoping to do with my CRS. i've spent all weekend reading wiki pages and forum posts and cannot seem to get this working:
*cable modem -> eth1 (gateway, need to implement masquerading so that eth2-16 have internet access)
*section 1 (ROUTING) = eth2-8 ---> statically assigned computers, rpi3, nas, wAP
*section 2 (VLAN1) = eth9-16 ------> internet access
*section 3 (VLAN2) = eth17-24 ----> LAN only, no internet access (IoT devices)
*SFP+ disabled*
*all VLANs should be able to talk to each other if possible. the purpose of VLAN2 is to prevent certain devices on my network from accessing the internet. i would also like to benefit from the wire-speed capabilities this device claims it can do between my computer and NAS.
thank you for reading, i hope to learn a lot here.