Hi,
First I would like to say thank you to the following members in no particular order: @sindy @CZFan and @acrul. I have read through your man post and a grateful for what I have gleaned.
But - I have been really struggling this week trying to get this sorted. I am hoping someone can set me straight. I am interested in making this work with RBX011 routers. I am going to start this out general and get to specific and end by posting my test config in an effort to help others. I will have different managed switches downstream - Unifi, netronix, cisco, etc... So to speak conceptually -
General - I would like the setup with 2 trunk ports that carry multiple VLANs in as a trunk. Lets say V100, V200 and V300 each with corresponding IP, DNS, DHCP, etc... and be filtered in the firewall using an address list.
RB3011 connections
ether1 - WAN
ether2 - Trunk 1 (V100, V200, V300)
ether3 - Trunk 2 (V100, V200, V300)
ether4 - access port vlan 100
ether5 - access port vlan 200
In the past when needed only one trunk port it was much easier as I can run the VLANs on the trunk interface (ether2) and created a bridge to tie the VLAN to any bridge along with any access port needed (VLAN100 > ether 4). I setup IP address and DHCP on the VLAN and it works fine. Pretty standard way to do it I believe - at the very least it worked.
Now I would like 2 trunk ports and use 6.41 and beyond. I have looked at several posts including sindy's #8 below:
viewtopic.php?f=2&t=133909&p=659104#p659104
I could make the 1st approach work by essentially creating a bridge for each vlan. I assume this is all CPU driven.
I then tried his 2nd example making one bridge and using the VLAN filtering (enabled) on the bridge. I could not get tags to pass on ether1 or ether3. I believe the access port worked however. This scenario makes the most sense to me because i can specify what is tagged and untagged by interface. Something like this with ether2-5 on the "my-bridge".
The Bridge/VLANs tab indicates they are "current tagged" - but the VLAN tags are not on the wire as in Option 1. It makes sense that it should work as it says "tagged", but I must be missing something.
This looked promising but do not work for me as well from CZFan. This is a bit different with assigning a PVID to the bridge port, and made sense, but did not work.
viewtopic.php?t=131079
Then I see others using the VLAN configuring in the switch menu. I have not had good success with this approach. For example:
viewtopic.php?f=2&t=82414&p=663097&hili ... ts#p663097
Can someone help me make sense of this? I am confused as to what role the bridge/vlan should play a part VS the switch settings. I appears that you can use some of both to get his done but it is lost on me. I am also a bit unclear as to what the performance ramifications either approach is.
Is the bridge approach a better option?
- create one bridge
- run the VLANs on the bridge
- add ports the bridge
- use the vlan tab to create trunk and access ports
- set IP addresses and DHCP on the VLANs.
- what role should bridge or port PVID play?
Thanks in advance for any all help. I am upset with myself that I cannot get my head around it. I can seem to get access ports up and running, but I cannot create multiple trunk ports - ugh. I hope this post will help others if they are in the same spot as me.