Physically I plan to use ether1 as my WAN-port (connected directly to the ethernet port on the ISP-supported fiber-router), ether2 as my LAN-port (connected to an unmangaged switch), and ether3 directly connected to my Ubiquiti AP (lets for argument sake say I want to use ether3, but in reality I might want to use ether10 with PoE in stead). As I want to allow my local network and the local "part" of Ubiquiti to communicate I guess both of these will use the same vlan (ID1). However as I don't want to let the guest network to have access to my local network (cabled and wifi) it should use vlan ID2.
Correct me if I am wrong. In this setup ether2 (LAN) should be untagged (vlan ID1) as my switch is unmanaged (all my cabled equipment is connected to this switch). The interface ether3 (Ubiquiti) is going to handle both private and guest-traffic so it should be setup tagged for both vlan ID1 and ID2 (naturally ID1 on both ether2 and ether3 needs to be able to communicate with each other).
Again correct me if I am wrong, this is how to set it up?
Code: Select all
/interface vlan
add interface=ether3 name=eth3-vlanLocal vlan-id=10
add interface=ether3 name=eth3-vlanGuest vlan-id=20
/interface bridge
add name=bridge-vlanLocal
/interface bridge port
add bridge=bridge-vlanLocal interface=eth3-vlanLocal
add bridge=bridge-vlanLocal interface=ether2
Pelle