I have stuck with this already few days trying to figure out how to properly set tagged and untagged vlans on RB1100Ahx2.
the principle diagram is here as an example: (pink is for testing, both cable ar not connected at the same cable) Cisco 1/0/3 UNtagged is connected to ether1 - port doesn't get up running, stays orange on cisco
re-plugging the same cable to:
Cisco 1/0/4 tagged ---> ether5 - ports works and everything is ok.
in production I have in place of Cisco an unmanaged HP switch, connecting RB1100Ahx2 hangs up all network...
Code: Select all
interface range GigabitEthernet1/0/1-3
switchport access vlan 2
switchport mode access
!
interface GigabitEthernet1/0/4
switchport trunk allowed vlan 2,10
switchport trunk native vlan 999
switchport mode trunk
!
----------------------------------------------------------------------------------------------
# jan/03/1970 01:48:04 by RouterOS 6.45.9
# model = 1100AHx2
/interface bridge
add name=bridge1
/interface vlan
add interface=bridge1 name=vlan2 vlan-id=2
/interface ethernet switch port
# ether1,ether2,ether3,ether4,ether5,switch2-cpu
set 0 default-vlan-id=2 vlan-header=always-strip vlan-mode=fallback # error here?
set 1 vlan-mode=secure
set 2 vlan-mode=secure
set 3 vlan-mode=secure
set 4 vlan-mode=secure
set 11 vlan-mode=secure
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=ether4
add bridge=bridge1 interface=ether5
/interface ethernet switch vlan
add independent-learning=yes ports=switch2-cpu,ether1,ether2,ether3,ether4,ether5 switch=switch2 vlan-id=2 # error here?
/ip address
add address=xxxxxxx interface=vlan2
/system package update
set channel=long-term
/system routerboard settings
set auto-upgrade=yes
https://wiki.mikrotik.com/wiki/Manual:S ... p_Features:
I'm assuming error is in one of those of two rows setting vlans, but have tried different settings, either doesn't work IP network from Mikrotik, either cisco blocks portNote: QCA8337 and Atheros8327 switch chips ignore the vlan-header property and uses the default-vlan-id property to determine which ports are access ports. The vlan-header is set to leave-as-is and cannot be changed while the default-vlan-id property should only be used on access ports to tag all ingress traffic.