I’m using the RB4011iGS and setup one simple LAN for all my devices at home.
All work well, no issues.
But I have a few IoT devices which I do not want in my private LAN, so I want to setup just one (1) VLAN for these devices.
I have read, read and read http://forum.mikrotik.com/viewtopic.php?t=143620 and especially the "Router-Switch-AP (all in one)" part and hope I understand what is written.
Below is what I have created and like to know from all the VLAN experts here on the forum if I need to fine-tune my creation and if so, how.
BTW: The creation work well and as I had in mind, but maybe it could better.
Thanks for all the help.
Code: Select all
# ether9 = PWR-Line
# wlan3 = Guest Wi-Fi
#######################################
# VLAN Overview
#######################################
# 20 = IoT
#######################################
# Bridge
#######################################
/interface bridge
add name=bridge1 vlan-filtering=yes
#######################################
# Access Ports & VLAN Security
#######################################
# ingress behavior
/interface bridge port
add bridge=bridge1 ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged pvid=20 interface=wlan3
set bridge=bridge1 ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged pvid=20 [find interface=ether9] comment=""
# egress behavior
/interface bridge vlan
add bridge=bridge1 tagged=bridge1 untagged=ether9,wlan3 vlan-ids=20
#######################################
# IP Services
#######################################
# VLAN20 interface creation, IP assignment, and DHCP service.
/interface vlan add interface=bridge1 name=vlan20 vlan-id=20
/ip address add address=10.10.20.1/24 interface=vlan20
/ip pool add name=vlan20-pool ranges=10.10.20.2-10.10.20.254
/ip dhcp-server add address-pool=vlan20-pool interface=vlan20 name=dhcp-vlan20
/ip dhcp-server network add address=10.10.20.0/24 dns-server=1.0.0.1 gateway=10.10.20.1
#######################################
# Firewalling & NAT
#######################################
/interface list add name=VLAN
/interface list member add interface=vlan20 list=VLAN