...and the config above is exactly a vlan-aware bridge. Aka "the new way".Just to give some information about this setup.
It is the old way by using many VLAN.
From 6.41 you can use Bridge aware VLAN.
Se some example here:
viewtopic.php?t=138232
You are running a router that does have a big security risk.# nov/09/2018 18:07:53 by RouterOS 6.35.4
# nov/11/2018 14:19:12 by RouterOS 6.43.4
# software id = Z0NI-ZVVR
#
# model = RouterBOARD 3011UiAS
# serial number = 71A00530D6DD
/interface bridge
add dhcp-snooping=yes fast-forward=no name=localnetwork
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN-Fiber
set [ find default-name=ether2 ] name=ether2-WAN-Cable
set [ find default-name=ether6 ] name=ether6-LAN
/interface vlan
add interface=localnetwork name=vlan_169_cams vlan-id=169
add interface=localnetwork name=vlan_170_dispatch vlan-id=170
add interface=localnetwork name=vlan_180_voice vlan-id=180
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=lan-dhcp ranges=192.168.168.50-192.168.168.220
add name=vlan-voice ranges=192.168.180.50-192.168.180.100
add name=vlan-cams ranges=192.168.169.2-192.168.169.10
add name=vlan-dispatch ranges=192.168.170.50-192.168.170.100
/ip dhcp-server
add address-pool=lan-dhcp disabled=no interface=localnetwork name=lan-dhcp
add address-pool=vlan-voice disabled=no interface=vlan_180_voice lease-time=\
24m name=vlan-voice
add address-pool=vlan-cams disabled=no interface=vlan_169_cams lease-time=24m \
name=vlan-cams
add address-pool=vlan-dispatch disabled=no interface=vlan_170_dispatch \
lease-time=24m name=vlan-dispatch-dhcp
/interface bridge port
add bridge=localnetwork interface=ether6-LAN
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork untagged=\
vlan_169_cams,vlan_170_dispatch,vlan_180_voice vlan-ids=180,169,170
/ip address
add address=192.168.168.1/24 interface=localnetwork network=192.168.168.0
add address=50.238.23.x/29 interface=ether1-WAN-Fiber network=\
50.238.x.x
add address=96.70.x.x/29 interface=ether2-WAN-Cable network=96.70.x.x
add address=192.168.180.1/24 interface=vlan_180_voice network=192.168.180.0
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.169.1/24 interface=vlan_170_dispatch network=\
192.168.169.0
/ip dhcp-server network
add address=192.168.168.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.168.1 \
netmask=24
add address=192.168.169.0/24 dns-server=8.8.8.8 gateway=192.168.169.1 \
netmask=24
add address=192.168.170.0/24 dns-server=8.8.8.8 gateway=192.168.170.1 \
netmask=24
add address=192.168.180.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.180.1
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall mangle
add action=mark-connection chain=prerouting connection-state=new \
in-interface=ether1-WAN-Fiber new-connection-mark=wan1 passthrough=yes
add action=mark-connection chain=prerouting connection-state=new \
in-interface=ether2-WAN-Cable new-connection-mark=wan2 passthrough=yes
add action=mark-routing chain=output connection-mark=wan1 new-routing-mark=\
wan1-out passthrough=yes
add action=mark-routing chain=output connection-mark=wan2 new-routing-mark=\
wan2-out passthrough=yes
add action=mark-connection chain=prerouting connection-state=new \
dst-address-type=!local in-interface=localnetwork new-connection-mark=\
wan1 passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=prerouting connection-state=new \
dst-address-type=!local in-interface=localnetwork new-connection-mark=\
wan2 passthrough=yes per-connection-classifier=both-addresses:2/1
add action=mark-routing chain=prerouting connection-mark=wan1 in-interface=\
localnetwork new-routing-mark=wan1output passthrough=yes
add action=mark-routing chain=prerouting connection-mark=wan2 in-interface=\
localnetwork new-routing-mark=wan2output passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-WAN-Fiber
add action=masquerade chain=srcnat out-interface=ether2-WAN-Cable
/ip route
add check-gateway=ping distance=1 gateway=50.238.x.x routing-mark=\
wan1output
add check-gateway=ping distance=2 gateway=96.70.x.x routing-mark=\
wan2output
add check-gateway=ping distance=1 gateway=50.238.x.x
add check-gateway=ping distance=2 gateway=96.70.x.x
/system clock
set time-zone-name=America/Chicago
/system routerboard settings
set silent-boot=no
vlan 169,180
!
!
!
interface GigabitEthernet3/0/1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
!
interface GigabitEthernet3/0/2 THIS WORKSWHEN PLUGGED LAPTOP HAS 180 IP
switchport access vlan 180
switchport mode access
!
interface GigabitEthernet3/0/3 THIS DOES NOW WORK!!!!!!!!!!!!!!!!
switchport mode access
!
interface GigabitEthernet3/0/4 THIS WORKS WHEN PLUGGED LAPTOP HAVE 169 IP
switchport access vlan 169
switchport mode access
switchport voice vlan 180
srr-queue bandwidth share 10 10 60 20
queue-set 2
spanning-tree portfast
!
interface GigabitEthernet3/0/5 THIS WORKS WHEN PLUGGED LAPTOP HAVE 168 IP
switchport mode access
switchport voice vlan 180
srr-queue bandwidth share 10 10 60 20
queue-set 2
spanning-tree portfast
interface GigabitEthernet3/0/6 works ok when plugged laptop have 168 ip
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=169
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=170
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=180
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=169,170,180
I will check this with cisco catalyst. theoretically all should be ok now, I dont know but I have feeling like that load balance does not work properly, most data goes thought Cable ISP which is a way slower, also ideally would be send all traffic http https + voip only thought Fiber isp# nov/13/2018 18:29:21 by RouterOS 6.43.4
# software id = Z0NI-ZVVR
#
# model = RouterBOARD 3011UiAS
# serial number = 71A00530D6DD
/interface bridge
add dhcp-snooping=yes fast-forward=no name=localnetwork vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN-Fiber
set [ find default-name=ether2 ] name=ether2-WAN-Cable
set [ find default-name=ether6 ] name=ether6-LAN
set [ find default-name=ether7 ] name=ether7-LAN
/interface vlan
add interface=localnetwork name=vlan_169_cams vlan-id=169
add interface=localnetwork name=vlan_170_dispatch vlan-id=170
add interface=localnetwork name=vlan_180_voice vlan-id=180
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip ipsec peer profile
set [ find default=yes ] dh-group=modp2048 enc-algorithm=aes-256,3des
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-256-cbc,aes-128-cbc lifetime=0s \
pfs-group=none
/ip pool
add name=lan-dhcp ranges=192.168.168.50-192.168.168.220
add name=vlan-voice ranges=192.168.180.50-192.168.180.100
add name=vlan-cams ranges=192.168.169.2-192.168.169.10
add name=vlan-dispatch ranges=192.168.170.50-192.168.170.100
add name=VPN-L2tp ranges=10.10.10.10-10.10.10.30
/ip dhcp-server
add address-pool=lan-dhcp disabled=no interface=localnetwork name=lan-dhcp
add address-pool=vlan-voice disabled=no interface=vlan_180_voice lease-time=\
24m name=vlan-voice
add address-pool=vlan-cams disabled=no interface=vlan_169_cams lease-time=24m \
name=vlan-cams
add address-pool=vlan-dispatch disabled=no interface=vlan_170_dispatch \
lease-time=24m name=vlan-dispatch-dhcp
/ppp profile
add dns-server=8.8.8.8,8.8.4.4 local-address=10.10.10.1 name=VPN-L2TP \
remote-address=VPN-L2tp use-encryption=required
/interface bridge port
add bridge=localnetwork interface=ether6-LAN
add bridge=localnetwork interface=ether7-LAN
/interface bridge vlan
add bridge=localnetwork tagged=vlan_169_cams,vlan_170_dispatch,vlan_180_voice \
untagged=localnetwork vlan-ids=169,170,180
/interface l2tp-server server
set authentication=mschap1,mschap2 default-profile=VPN-L2TP enabled=yes \
keepalive-timeout=disabled
/ip address
add address=192.168.168.1/24 interface=localnetwork network=192.168.168.0
add address=50.238/29 interface=ether1-WAN-Fiber network=\
50.238
add address=96.70/29 interface=ether2-WAN-Cable network=96.70
add address=192.168.180.1/24 interface=vlan_180_voice network=192.168.180.0
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.169.1/24 interface=vlan_170_dispatch network=\
192.168.169.0
/ip dhcp-server network
add address=192.168.168.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.168.1 \
netmask=24
add address=192.168.169.0/24 dns-server=8.8.8.8 gateway=192.168.169.1 \
netmask=24
add address=192.168.170.0/24 dns-server=8.8.8.8 gateway=192.168.170.1 \
netmask=24
add address=192.168.180.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=192.168.180.1
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall filter
add action=accept chain=input dst-port=1701 protocol=udp
add action=accept chain=input dst-port=500 protocol=udp
add action=accept chain=input dst-port=4500 protocol=udp
add action=accept chain=input protocol=ipsec-ah
add action=accept chain=input protocol=ipsec-esp
/ip firewall mangle
add action=mark-connection chain=prerouting connection-state=new \
in-interface=ether1-WAN-Fiber new-connection-mark=wan1 passthrough=yes
add action=mark-connection chain=prerouting connection-state=new \
in-interface=ether2-WAN-Cable new-connection-mark=wan2 passthrough=yes
add action=mark-routing chain=output connection-mark=wan1 new-routing-mark=\
wan1-out passthrough=yes
add action=mark-routing chain=output connection-mark=wan2 new-routing-mark=\
wan2-out passthrough=yes
add action=mark-connection chain=prerouting connection-state=new \
dst-address-type=!local in-interface=localnetwork new-connection-mark=\
wan1 passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=prerouting connection-state=new \
dst-address-type=!local in-interface=localnetwork new-connection-mark=\
wan2 passthrough=yes per-connection-classifier=both-addresses:2/1
add action=mark-routing chain=prerouting connection-mark=wan1 in-interface=\
localnetwork new-routing-mark=wan1output passthrough=yes
add action=mark-routing chain=prerouting connection-mark=wan2 in-interface=\
localnetwork new-routing-mark=wan2output passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-WAN-Fiber
add action=masquerade chain=srcnat out-interface=ether2-WAN-Cable
add action=masquerade chain=srcnat comment="NAT L2TP/IPSEC" src-address=\
10.10.10.0/24
/ip ipsec peer
add address=0.0.0.0/0 exchange-mode=main-l2tp generate-policy=port-override \
passive=yes secret=12345
/ip route
add check-gateway=ping distance=1 gateway=50.238. routing-mark=\
wan1output
add check-gateway=ping distance=2 gateway=96.70. routing-mark=\
wan2output
add check-gateway=ping distance=1 gateway=50.238.
add check-gateway=ping distance=2 gateway=96.70.
/lcd
set time-interval=daily
/ppp secret
add name=test password=test profile=VPN-L2TP service=l2tp
/system clock
set time-zone-name=America/Chicago
/system routerboard settings
set silent-boot=no
/interface bridge vlan
add bridge=localnetwork tagged=vlan_169_cams,vlan_170_dispatch,vlan_180_voice \
untagged=localnetwork vlan-ids=169,170,180
Untagged vlan 1
Tagged 168,170, 180
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork, ether6-LAN, ether7-LAN vlan-ids=169,170,180
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.169.1/24 interface=vlan_170_dispatch network=192.168.169.0
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.170.1/24 interface=vlan_170_dispatch network=192.168.170.0
/ip dhcp-server network
add address=192.168.168.0/24 dns-server=192.168.168.1 gateway=192.168.168.1 netmask=24
add address=192.168.169.0/24 dns-server=192.168.168.1 gateway=192.168.169.1 netmask=24
add address=192.168.170.0/24 dns-server=192.168.168.1 gateway=192.168.170.1 netmask=24
add address=192.168.180.0/24 dns-server=192.168.168.1 gateway=192.168.180.1 netmask=24
This is the correct way to do it for the new Vlan aware Bridge configuration in Router OS 6.41 or larger.I see now "You are connecting the Bridge/Vlan to the VLAN interface. It should be connected to the physical Interfaces"
/interface bridge
add fast-forward=no name=localnetwork
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN1
set [ find default-name=ether2 ] name=ether2-WAN2
set [ find default-name=ether6 ] name=ether6-LAN
set [ find default-name=ether7 ] name=ether7-LAN
/interface vlan
add interface=ether6-LAN name=vlan_169_cams vlan-id=169
add interface=ether6-LAN name=vlan_170_dispatch vlan-id=170
add interface=ether6-LAN name=vlan_171_acct vlan-id=171
add interface=ether6-LAN name=vlan_172_printers vlan-id=172
add interface=ether6-LAN name=vlan_173_warehouse vlan-id=173
add interface=ether6-LAN name=vlan_180_voice vlan-id=180
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=lan-pool ranges=192.168.168.50-192.168.168.200
add name=vlan170-pool ranges=192.168.170.50-192.168.170.100
add name=vlan169-pool ranges=192.168.169.20-192.168.169.50
add name=vlan180-pool ranges=192.168.180.50-192.168.180.100
add name=vlan171-pool ranges=192.168.171.50-192.168.171.100
add name=vlan172-pool ranges=192.168.172.50-192.168.172.100
add name=vlan173-pool ranges=192.168.173.50-192.168.173.100
/ip dhcp-server
add address-pool=lan-pool disabled=no interface=localnetwork lease-time=24m \
name=dhcp1-localLAN
add address-pool=vlan169-pool disabled=no interface=vlan_169_cams lease-time=\
24m name=dhcp_vlan169
add address-pool=vlan170-pool disabled=no interface=vlan_170_dispatch \
lease-time=24m name=dhcp_vlan170
add address-pool=vlan171-pool disabled=no interface=vlan_171_acct lease-time=\
24m name=dhcp_vlan171
add address-pool=vlan172-pool disabled=no interface=vlan_172_printers \
lease-time=24m name=dhcp_vlan172
add address-pool=vlan180-pool disabled=no interface=vlan_180_voice \
lease-time=24m name=dhcp_vlan180
/interface bridge port
add bridge=localnetwork interface=ether6-LAN
add bridge=localnetwork interface=ether7-LAN
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN,ether7-LAN vlan-ids=\
169,170,171,172,173,180
/ip address
add address=50.238.x.x/29 interface=ether1-WAN1 network=50.238.x.x
add address=96.70.x.x/29 interface=ether2-WAN2 network=96.70.x.x
add address=192.168.168.1/24 interface=localnetwork network=192.168.168.0
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.170.1/24 interface=vlan_170_dispatch network=\
192.168.170.0
add address=192.168.171.1/24 interface=vlan_171_acct network=192.168.171.0
add address=192.168.172.1/24 interface=vlan_172_printers network=\
192.168.172.0
add address=192.168.173.1/24 interface=vlan_173_warehouse network=\
192.168.173.0
add address=192.168.180.1/24 interface=vlan_180_voice network=192.168.180.0
/ip dhcp-server network
add address=192.168.168.0/24 dns-server=192.168.168.1 gateway=192.168.168.1
add address=192.168.169.0/24 dns-server=192.168.169.1 gateway=192.168.169.1 \
netmask=24
add address=192.168.170.0/24 dns-server=192.168.170.1 gateway=192.168.170.1 \
netmask=24
add address=192.168.171.0/24 dns-server=192.168.171.1 gateway=192.168.171.1 \
netmask=24
add address=192.168.172.0/24 dns-server=192.168.172.1 gateway=192.168.172.1 \
netmask=24
add address=192.168.173.0/24 dns-server=192.168.173.1 gateway=192.168.173.1 \
netmask=24
add address=192.168.180.0/24 dns-server=192.168.180.1 gateway=192.168.180.1 \
netmask=24
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall mangle
add action=mark-connection chain=input in-interface=ether1-WAN1 \
new-connection-mark=WAN1_connmark passthrough=yes
add action=mark-connection chain=input in-interface=ether2-WAN2 \
new-connection-mark=WAN2_connmark passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_connmark \
new-routing-mark=ke_WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_connmark \
new-routing-mark=ke_WAN2 passthrough=yes
add action=mark-connection chain=prerouting dst-address-type=!local \
in-interface=localnetwork new-connection-mark=WAN1_connmark passthrough=\
yes per-connection-classifier=both-addresses-and-ports:2/0
add action=mark-connection chain=prerouting dst-address-type=!multicast \
in-interface=localnetwork new-connection-mark=WAN2_connmark passthrough=\
yes per-connection-classifier=both-addresses-and-ports:2/1
add action=mark-routing chain=prerouting connection-mark=WAN1_connmark \
in-interface=localnetwork new-routing-mark=ke_WAN1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_connmark \
in-interface=localnetwork new-routing-mark=ke_WAN2 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-WAN1
add action=masquerade chain=srcnat out-interface=ether2-WAN2
/ip route
add check-gateway=ping distance=1 gateway=8.8.8.8 routing-mark=ke_WAN1
add distance=1 gateway=10.20.30.1 routing-mark=ke_WAN1
add check-gateway=ping distance=2 gateway=8.8.8.8 routing-mark=ke_WAN2
add distance=2 gateway=10.20.30.2 routing-mark=ke_WAN2
add distance=1 dst-address=8.8.8.8/32 gateway=50.238.x.x scope=10
add distance=1 dst-address=8.8.8.8/32 gateway=96.70.x.x scope=10
add check-gateway=ping distance=1 dst-address=10.20.30.1/32 gateway=8.8.8.8 \
scope=10
add check-gateway=ping distance=1 dst-address=10.20.30.2/32 gateway=8.8.4.4 \
scope=10
/system routerboard settings
set silent-boot=no
/interface bridge
add fast-forward=no name=localnetwork vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN1
set [ find default-name=ether2 ] name=ether2-WAN2
set [ find default-name=ether6 ] name=ether6-LAN
set [ find default-name=ether7 ] name=ether7-LAN
/interface vlan
add interface=localnetwork name=vlan_169_cams vlan-id=169
add interface=localnetwork name=vlan_170_dispatch vlan-id=170
add interface=localnetwork name=vlan_171_acct vlan-id=171
add interface=localnetwork name=vlan_172_printers vlan-id=172
add interface=localnetwork name=vlan_173_warehouse vlan-id=173
add interface=localnetwork name=vlan_180_voice vlan-id=180
add bridge=localnetwork tagged=localnetwork,ether6-LAN,ether7-LAN vlan-ids=169,170,171,172,173,180
/ip address
add address=50.238.x.x/29 interface=ether1-WAN1 network=50.238.x.x
add address=96.70.x.x/29 interface=ether2-WAN2 network=96.70.x.x
add address=192.168.168.1/24 interface=localnetwork network=192.168.168.0
add address=192.168.169.1/24 interface=vlan_169_cams network=192.168.169.0
add address=192.168.170.1/24 interface=vlan_170_dispatch network=192.168.170.0
add address=192.168.171.1/24 interface=vlan_171_acct network=192.168.171.0
add address=192.168.172.1/24 interface=vlan_172_printers network=192.168.172.0
add address=192.168.173.1/24 interface=vlan_173_warehouse network=192.168.173.0
add address=192.168.180.1/24 interface=vlan_180_voice network=192.168.180.0
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=169
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=170
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=180
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN vlan-ids=169,170,180
/interface bridge
add fast-forward=no name=localnetwork
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN1
set [ find default-name=ether2 ] name=ether2-WAN2
set [ find default-name=ether6 ] name=ether6-LAN
set [ find default-name=ether7 ] name=ether7-LAN
/interface vlan
add interface=localnetwork name=vlan_169_cams vlan-id=169
add interface=localnetwork name=vlan_170_dispatch vlan-id=170
add interface=localnetwork name=vlan_171_acct vlan-id=171
add interface=localnetwork name=vlan_172_printers vlan-id=172
add interface=localnetwork name=vlan_173_warehouse vlan-id=173
add interface=localnetwork name=vlan_180_voice vlan-id=180
/interface bridge port
add bridge=localnetwork interface=ether6-LAN
add bridge=localnetwork interface=ether7-LAN
/interface bridge vlan
add bridge=localnetwork tagged=localnetwork,ether6-LAN,ether7-LAN vlan-ids=\
169,170,171,172,173,180
[admin@MikroTik] >
[admin@MikroTik] >
[admin@MikroTik] >
[admin@MikroTik] >
[admin@MikroTik] > interface bridge
[admin@MikroTik] /interface bridge> add fast-forward=no name=bridge1 vlan-filtering=no
[admin@MikroTik] /interface bridge> /
[admin@MikroTik] > interface ethernet
[admin@MikroTik] /interface ethernet> set [ find default-name=ether6 ] name=ether6-LAN
[admin@MikroTik] /interface ethernet> set [ find default-name=ether7 ] name=ether7-LAN
[admin@MikroTik] /interface ethernet> /
[admin@MikroTik] > interface vlan
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan169 vlan-id=169
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan170 vlan-id=170
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan171 vlan-id=171
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan172\ vlan-id=172
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan172 vlan-id=172
failure: already have interface with such name
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan173 vlan-id=173
[admin@MikroTik] /interface vlan> add interface=bridge1 name=vlan180 vlan-id=180
[admin@MikroTik] /interface vlan>
[admin@MikroTik] /interface vlan>
[admin@MikroTik] /interface vlan>
[admin@MikroTik] /interface vlan> /
[admin@MikroTik] > interface bridge vlan
[admin@MikroTik] /interface bridge vlan> add bridge=bridge1 tagged=bridge1,ether6-LAN,ether7-LAN vlan-ids=169,170,171,172,173,180
[admin@MikroTik] /interface bridge vlan> /
[admin@MikroTik] > interface bridge
[admin@MikroTik] /interface bridge> add vlan-filtering=yes
[admin@MikroTik] /interface bridge>
[admin@MikroTik] /interface bridge>
[admin@MikroTik] /interface bridge>
[admin@MikroTik] /interface bridge> /
[admin@MikroTik] > ip address
[admin@MikroTik] /ip address> add address=192.168.168.1/24 interface=bridge1 network=192.168.168.0
[admin@MikroTik] /ip address> add address=192.168.169.1/24 interface=vlan169 network=192.168.169.0
[admin@MikroTik] /ip address> add address=192.168.170.1/24 interface=vlan170 network=192.168.170.0
[admin@MikroTik] /ip address> add address=192.168.171.1/24 interface=vlan171 network=192.168.171.0
[admin@MikroTik] /ip address> add address=192.168.172.1/24 interface=vlan172 network=192.168.172.0
[admin@MikroTik] /ip address> add address=192.168.173.1/24 interface=vlan173 network=192.168.173.0
[admin@MikroTik] /ip address> add address=192.168.180.1/24 interface=vlan180 network=192.168.180.0
[admin@MikroTik] /ip address>
[admin@MikroTik] /ip address>
[admin@MikroTik] /ip address>
[admin@MikroTik] /ip address> /
[admin@MikroTik] > ip pool
[admin@MikroTik] /ip pool>
[admin@MikroTik] /ip pool> add name=lan ranges=192.168.168.50-192.168.168.100
[admin@MikroTik] /ip pool> add name=v169 ranges=192.168.169.50-192.168.169.100
[admin@MikroTik] /ip pool> add name=v170 ranges=192.168.170.50-192.168.170.100
[admin@MikroTik] /ip pool> add name=v171 ranges=192.168.171.50-192.168.171.100
[admin@MikroTik] /ip pool> add name=v172 ranges=192.168.172.50-192.168.172.100
[admin@MikroTik] /ip pool> add name=v173 ranges=192.168.173.50-192.168.173.100
[admin@MikroTik] /ip pool> add name=v180 ranges=192.168.180.50-192.168.180.100
[admin@MikroTik] /ip pool>
[admin@MikroTik] /ip pool> /
[admin@MikroTik] > ip dhcp-server
[admin@MikroTik] /ip dhcp-server network> add address=192.168.169.0/24 gateway=192.168.169.1 dns-server=192.168.169.1
[admin@MikroTik] /ip dhcp-server network> add address=192.168.170.0/24 gateway=192.168.170.1 dns-server=192.168.170.1
[admin@MikroTik] /ip dhcp-server network> add address=192.168.168.0/24 gateway=192.168.168.1 dns-server=192.168.168.1
failure: such network already exists
[admin@MikroTik] /ip dhcp-server network> add address=192.168.171.0/24 gateway=192.168.171.1 dns-server=192.168.171.1
[admin@MikroTik] /ip dhcp-server network> add address=192.168.172.0/24 gateway=192.168.172.1 dns-server=192.168.172.1
[admin@MikroTik] /ip dhcp-server network> add address=192.168.173.0/24 gateway=192.168.173.1 dns-server=192.168.173.1
[admin@MikroTik] /ip dhcp-server> add name=bridge1 address-pool=lan interface=bridge1 lease-time=00:24:00
[admin@MikroTik] /ip dhcp-server>
[admin
@Mikro
Tik] /
ip dhc
p-serv
[admin@MikroTik] /ip dhcp-server> add name=v169 address-pool=v169 interface=vlan169 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server> add name=v170 address-pool=v170 interface=vlan170 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server> add name=v171 address-pool=v171 interface=vlan171 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server> add name=v172 address-pool=v172 interface=vlan172 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server> add name=v173 address-pool=v173 interface=vlan173 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server> add name=v180 address-pool=v180 interface=vlan180 lease-time=00:24:00 disabled=no
[admin@MikroTik] /ip dhcp-server network> add address=192.168.180.0/24 gateway=192.168.180.1 dns-server=192.168.180.1
/interface bridge
add fast-forward=no name=bridge1 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether6 ] name=ether6-LAN
set [ find default-name=ether7 ] name=ether7-LAN
/interface vlan
add interface=bridge1 name=vlan169 vlan-id=169
add interface=bridge1 name=vlan170 vlan-id=170
add interface=bridge1 name=vlan171 vlan-id=171
add interface=bridge1 name=vlan172 vlan-id=172
add interface=bridge1 name=vlan173 vlan-id=173
add interface=bridge1 name=vlan180 vlan-id=180
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=lan ranges=192.168.168.50-192.168.168.100
add name=v169 ranges=192.168.169.50-192.168.169.100
add name=v170 ranges=192.168.170.50-192.168.170.100
add name=v171 ranges=192.168.171.50-192.168.171.100
add name=v172 ranges=192.168.172.50-192.168.172.100
add name=v173 ranges=192.168.173.50-192.168.173.100
add name=v180 ranges=192.168.180.50-192.168.180.100
/ip dhcp-server
add address-pool=lan disabled=no interface=bridge1 lease-time=24m name=bridge1
add address-pool=v169 disabled=no interface=vlan169 lease-time=24m name=v169
add address-pool=v170 disabled=no interface=vlan170 lease-time=24m name=v170
add address-pool=v171 disabled=no interface=vlan171 lease-time=24m name=v171
add address-pool=v172 disabled=no interface=vlan172 lease-time=24m name=v172
add address-pool=v173 disabled=no interface=vlan173 lease-time=24m name=v173
add address-pool=v180 disabled=no interface=vlan180 lease-time=24m name=v180
/interface bridge vlan
add bridge=bridge1 tagged=bridge1,ether6-LAN,ether7-LAN vlan-ids=169,170,171,172,173,180
/ip address
add address=192.168.168.1/24 interface=bridge1 network=192.168.168.0
add address=192.168.169.1/24 interface=vlan169 network=192.168.169.0
add address=192.168.170.1/24 interface=vlan170 network=192.168.170.0
add address=192.168.171.1/24 interface=vlan171 network=192.168.171.0
add address=192.168.172.1/24 interface=vlan172 network=192.168.172.0
add address=192.168.173.1/24 interface=vlan173 network=192.168.173.0
add address=192.168.180.1/24 interface=vlan180 network=192.168.180.0
/ip dhcp-server network
add address=192.168.168.0/24 dns-server=192.168.168.1 gateway=192.168.168.1
add address=192.168.169.0/24 dns-server=192.168.169.1 gateway=192.168.169.1
add address=192.168.170.0/24 dns-server=192.168.170.1 gateway=192.168.170.1
add address=192.168.171.0/24 dns-server=192.168.171.1 gateway=192.168.171.1
add address=192.168.172.0/24 dns-server=192.168.172.1 gateway=192.168.172.1
add address=192.168.173.0/24 dns-server=192.168.173.1 gateway=192.168.173.1
add address=192.168.180.0/24 dns-server=192.168.180.1 gateway=192.168.180.1
/system routerboard settings
set silent-boot=no
interface GigabitEthernet3/0/1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
!
interface GigabitEthernet3/0/2
switchport access vlan 180
switchport mode access
!
interface GigabitEthernet3/0/3
switchport mode access
!
interface GigabitEthernet3/0/4
switchport access vlan 169
switchport mode access
switchport voice vlan 180
srr-queue bandwidth share 10 10 60 20
queue-set 2
spanning-tree portfast
!
interface GigabitEthernet3/0/5
switchport mode access
switchport voice vlan 180
srr-queue bandwidth share 10 10 60 20
queue-set 2
spanning-tree portfast
/interface bridge port
add bridge=bridge1 interface=ether6 pvid=1
add bridge=bridge1 interface=ether7 pvid=1
vlan 169
name vlan_169
vlan 170
name vlan_170
etc
The post from sunday at 9:14 pm./interface bridge
add fast-forward=no name=bridge1 vlan-filtering=yesCode: Select all/interface ethernet set [ find default-name=ether6 ] name=ether6-LAN set [ find default-name=ether7 ] name=ether7-LAN /interface vlan add interface=bridge1 name=vlan169 vlan-id=169 add interface=bridge1 name=vlan170 vlan-id=170 add interface=bridge1 name=vlan171 vlan-id=171 add interface=bridge1 name=vlan172 vlan-id=172 add interface=bridge1 name=vlan173 vlan-id=173 add interface=bridge1 name=vlan180 vlan-id=180 /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip pool add name=lan ranges=192.168.168.50-192.168.168.100 add name=v169 ranges=192.168.169.50-192.168.169.100 add name=v170 ranges=192.168.170.50-192.168.170.100 add name=v171 ranges=192.168.171.50-192.168.171.100 add name=v172 ranges=192.168.172.50-192.168.172.100 add name=v173 ranges=192.168.173.50-192.168.173.100 add name=v180 ranges=192.168.180.50-192.168.180.100 /ip dhcp-server add address-pool=lan disabled=no interface=bridge1 lease-time=24m name=bridge1 add address-pool=v169 disabled=no interface=vlan169 lease-time=24m name=v169 add address-pool=v170 disabled=no interface=vlan170 lease-time=24m name=v170 add address-pool=v171 disabled=no interface=vlan171 lease-time=24m name=v171 add address-pool=v172 disabled=no interface=vlan172 lease-time=24m name=v172 add address-pool=v173 disabled=no interface=vlan173 lease-time=24m name=v173 add address-pool=v180 disabled=no interface=vlan180 lease-time=24m name=v180 /interface bridge vlan add bridge=bridge1 tagged=bridge1,ether6-LAN,ether7-LAN vlan-ids=169,170,171,172,173,180 /ip address add address=192.168.168.1/24 interface=bridge1 network=192.168.168.0 add address=192.168.169.1/24 interface=vlan169 network=192.168.169.0 add address=192.168.170.1/24 interface=vlan170 network=192.168.170.0 add address=192.168.171.1/24 interface=vlan171 network=192.168.171.0 add address=192.168.172.1/24 interface=vlan172 network=192.168.172.0 add address=192.168.173.1/24 interface=vlan173 network=192.168.173.0 add address=192.168.180.1/24 interface=vlan180 network=192.168.180.0 /ip dhcp-server network add address=192.168.168.0/24 dns-server=192.168.168.1 gateway=192.168.168.1 add address=192.168.169.0/24 dns-server=192.168.169.1 gateway=192.168.169.1 add address=192.168.170.0/24 dns-server=192.168.170.1 gateway=192.168.170.1 add address=192.168.171.0/24 dns-server=192.168.171.1 gateway=192.168.171.1 add address=192.168.172.0/24 dns-server=192.168.172.1 gateway=192.168.172.1 add address=192.168.173.0/24 dns-server=192.168.173.1 gateway=192.168.173.1 add address=192.168.180.0/24 dns-server=192.168.180.1 gateway=192.168.180.1 /system routerboard settings set silent-boot=no
/interface bridge settings print
use-ip-firewall: no
use-ip-firewall-for-vlan: no
use-ip-firewall-for-pppoe: no
allow-fast-path: yes
bridge-fast-path-active: yes
bridge-fast-path-packets: 0
bridge-fast-path-bytes: 0
bridge-fast-forward-packets: 0
bridge-fast-forward-bytes: 0
/export hide-sensitive