I am using a HAPAC2 (Atheros 8327 switch chip) purely as a switch, in a VLAN environment. The reason I am using the switch chip, correct me if I am wrong, is my understanding that enabling vlans on the bridge will disable hardware offloading and will reduce the throughput of the HAPAC2 as a switch since all traffic will have to go through the CPU.
Port 1-4 are trunk ports : 1 = uplink, 2 = downlink, 3 and 4 = to Unifi APs which will tag particular SSIDs to a vlan.
Port 5 is an access port for VLAN 5.
I would like devices plugged into ports 2-4 to default to VLAN98. There is a hotspot running on this vlan, so if an anonymous device connects to an unprotected network jack, it is in the protected hotspot VLAN. That is my idea of protecting the network from anonymous devices. I would like the HAPAC2's mgmt vlan to be VL3.
Questions:
1. Do I need to create a bridge and add all ether ports to the bridge?
2. How do I set the HAPAC2's mgmt vlan to VL3?
3. I'm stumped on how to set the switch chip so that a random device plugged into say, port 3, will get the address on the existing dhcp server for VL98.
------
These are the relevant settings. There is no bridge set.
/interface ethernet switch port
set 0 vlan-mode=fallback
set 1 vlan-mode=fallback
set 2 vlan-mode=fallback
set 3 vlan-mode=fallback
set 4 default-vlan-id=5 vlan-header=always-strip vlan-mode=fallback
set 5 vlan-mode=fallback
/interface ethernet switch vlan
add independent-learning=yes ports=ether1,ether2,ether3,ether4,switch1-cpu switch=switch1 vlan-id=1
add independent-learning=yes ports=ether1,ether2,ether3,ether4,switch1-cpu switch=switch1 vlan-id=3
add independent-learning=yes ports=ether1,ether2,ether3,ether4,ether5 switch=switch1 vlan-id=5
add independent-learning=yes ports=ether1,ether2,ether3,ether4 switch=switch1 vlan-id=99
add independent-learning=yes ports=ether1,ether2,ether3,ether4 switch=switch1 vlan-id=98
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=ether1