Hello Folks!
This is about CCR1009-8 with the switch chip.
The CCR is used as primary router between various vlans and is also default gw for some of them.
I wanted to use the builtin switch chip, having ether1 and ether4 as vlan trunks going to one each CRS125.
ether2 I connect to incoming internet (a /28 subnet) as access port connected to one of the internal vlans that is trunked out to the CRS:es.
This topic is alos threaded from: viewtopic.php?f=2&t=142128 but with a little different setup.
Everything works, except one little detail, the accessport ether2, it has no connection to incoming internet and the public gw.
I tried to reconfigure so ether2 was access point to one of the internal network that has a DHCP server, and then attach a laptop to ether2, I got link up but that is all.
I must have missed or misunderstood something, yet I followed, how hard can it be :
https://wiki.mikrotik.com/wiki/Manual:S ... p_Features
https://wiki.mikrotik.com/wiki/Manual:B ... _switching
https://wiki.mikrotik.com/wiki/Manual:Switch_Router
(I know, I should get another "core" switch for it, my vendor told me, and I will put in one such later on. Meanwhile I would like to have something like this below.)
Here is how I set it up:
# CCR vlans
/interface bridge
add name=bridge1 protocol-mode=none
#
/interface bridge port
add bridge=bridge1 interface=ether1 hw=yes comment=trunk
add bridge=bridge1 interface=ether2 hw=yes comment=pub1
add bridge=bridge1 interface=ether4 hw=yes comment=trunk
#
#
/interface ethernet switch vlan
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=20
add ports ether1,ether4 switch=switch1 vlan-id=110
add ports switch1-cpu,ether1,ether2,ether4 switch=switch1 vlan-id=112
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=200
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=220
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=300
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=310
add ports ether1,ether4 switch=switch1 vlan-id=320
add ports switch1-cpu,ether1,ether4 switch=switch1 vlan-id=400
#
/interface ethernet switch port
set ether1 vlan-mode=secure vlan-header=add-if-missing
set ether2 vlan-mode=secure vlan-header=always-strip default-vlan-id=112 comment=pub1
set ether4 vlan-mode=secure vlan-header=add-if-missing
set switch1-cpu vlan-header=leave-as-is vlan-mode=secure
#
# Accessible IP addresses on one VLAN
/interface vlan
add interface=bridge1 vlan-id=20 name=vlan20
add interface=bridge1 vlan-id=112 name=pub1
add interface=bridge1 vlan-id=200 name=vlan200
add interface=bridge1 vlan-id=220 name=vlan220
add interface=bridge1 vlan-id=300 name=vlan300
add interface=bridge1 vlan-id=310 name=vlan310
add interface=bridge1 vlan-id=400 name=vlan400
#
/ip address
add address=<public-ip-addess> interface=pub1
add address=192.168.1.1/24 interface=vlan20
add address=172.16.1.1/24 interface=vlan200
add address=10.30.0.1/24 interface=vlan220
add address=192.168.2.254/24 interface=vlan300
add address=192.168.2.254/24 interface=vlan310
add address=172.16.16.3/24 interface=vlan400