I want 4 VLANs on the CCR with IP addresses and DHCP server configured on.
I want to transfer these VLAN networks to my CRS-328 via a SFP1 trunk.
I don't get IP addresses distributed on the CRS-328
What am I doing wrong? I think it depends on the configuration of the CCR.
Who can help me clarify this.
CCR-1036
Code: Select all
/interface ethernet
set [ find default-name=ether1 ] name=ether1-wan
/interface vlan
add interface=sfp-sfpplus1 name=vlan1-management vlan-id=1
add comment=secure-network interface=sfp-sfpplus1 name=vlan100-secure use-service-tag=yes vlan-id=100
add comment=unsecure-network interface=sfp-sfpplus1 name=vlan110-unsucure use-service-tag=yes vlan-id=110
add comment=synology-survey interface=sfp-sfpplus1 name=vlan120-synology-survey use-service-tag=yes vlan-id=120
/interface list
add name=WAN
add name=VLAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=pool-secure-network ranges=10.10.100.50-10.10.100.254
add name=pool-unsecure-network ranges=10.10.110.50-10.10.110.254
add name=pool-synology-survey ranges=10.10.120.50-10.10.120.254
add name=pool-management ranges=10.10.99.2-10.10.99.254
/ip dhcp-server
add address-pool=pool-secure-network disabled=no interface=vlan100-secure lease-time=1d name=dhcp-secure-network
add address-pool=pool-unsecure-network disabled=no interface=vlan110-unsucure lease-time=1d name=dhcp-unsecure-network
add address-pool=pool-synology-survey disabled=no interface=vlan120-synology-survey lease-time=1d name=dhcp-synology-survey
add address-pool=pool-management disabled=no interface=vlan1-management lease-time=1d name=dhcp-management
/tool user-manager customer
set admin access=own-routers,own-users,own-profiles,own-limits,config-payment-gw
/interface list member
add interface=ether1-wan list=WAN
/ip address
add address=10.10.100.1/24 comment=secure-network interface=vlan100-secure network=10.10.100.0
add address=10.10.110.1/24 comment=unsecure-network interface=vlan110-unsucure network=10.10.110.0
add address=10.10.120.1/24 comment=synology-survey interface=vlan120-synology-survey network=10.10.120.0
add address=10.10.99.1/24 comment=management interface=vlan1-management network=10.10.99.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether1-wan
/ip dhcp-server network
add address=10.10.99.0/24 gateway=10.10.99.1
add address=10.10.100.0/24 gateway=10.10.100.1
add address=10.10.110.0/24 gateway=10.10.110.1
add address=10.10.120.0/24 gateway=10.10.120.1
/ip firewall address-list
add address=10.10.99.0/24 list=vlans
add address=10.10.100.0/24 list=vlans
add address=10.10.110.0/24 list=vlans
add address=10.10.120.0/24 list=vlans
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN protocol=tcp src-address-list=vlans
/system clock
set time-zone-name=Europe/Brussels
/system routerboard settings
set protected-routerboot=enabled
/tool user-manager database
set db-path=user-manager
Code: Select all
/interface bridge
add admin-mac=74:4D:28:34:AE:46 auto-mac=no comment=defconf frame-types=admit-only-vlan-tagged ingress-filtering=yes name=bridge vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name=ether1-secure
set [ find default-name=ether2 ] name=ether2-secure
set [ find default-name=ether3 ] name=ether3-secure
set [ find default-name=ether4 ] name=ether4-secure
set [ find default-name=ether5 ] name=ether5-secure
set [ find default-name=ether6 ] name=ether6-secure
set [ find default-name=ether7 ] name=ether7-secure
set [ find default-name=ether8 ] name=ether8-secure
set [ find default-name=ether9 ] name=ether9-unsecure poe-voltage=low
set [ find default-name=ether10 ] name=ether10-unsecure
set [ find default-name=ether11 ] name=ether11-unsecure
set [ find default-name=ether12 ] name=ether12-unsecure
set [ find default-name=ether13 ] name=ether13-unsecure
set [ find default-name=ether14 ] name=ether14-unsecure
set [ find default-name=ether15 ] name=ether15-unsecure
set [ find default-name=ether16 ] name=ether16-unsecure
set [ find default-name=ether17 ] name=ether17-synology-survey
set [ find default-name=ether18 ] name=ether18-synology-survey
set [ find default-name=ether19 ] name=ether19-synology-survey
set [ find default-name=ether20 ] name=ether20-synology-survey
set [ find default-name=ether21 ] name=ether21-synology-survey
set [ find default-name=ether22 ] name=ether22-synology-survey
set [ find default-name=ether23 ] name=ether23-synology-survey
set [ find default-name=ether24 ] name=ether24-management
set [ find default-name=sfp-sfpplus1 ] name="sfp-sfpplus1-vlan-trunk -> CCR-1036"
set [ find default-name=sfp-sfpplus2 ] name="sfp-sfpplus2-vlan-trunk -> CRS-326"
set [ find default-name=sfp-sfpplus3 ] disabled=yes
set [ find default-name=sfp-sfpplus4 ] disabled=yes
/interface list
add name=VLAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether1-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether2-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether3-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether4-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether5-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether6-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether7-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether8-secure pvid=100
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether9-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether10-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether11-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether12-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether13-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether14-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether15-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether16-unsecure pvid=110
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether17-synology-survey pvid=120
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether18-synology-survey pvid=120
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether19-synology-survey pvid=120
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether20-synology-survey pvid=120
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether21-synology-survey pvid=120
add bridge=bridge comment=defconf ingress-filtering=yes interface=ether22-synology-survey pvid=120
add bridge=bridge ingress-filtering=yes interface=ether23-synology-survey pvid=120
add bridge=bridge interface=ether24-management
add bridge=bridge interface="sfp-sfpplus1-vlan-trunk -> CCR-1036"
/interface bridge settings
set use-ip-firewall=yes use-ip-firewall-for-vlan=yes
/ip neighbor discovery-settings
set discover-interface-list=VLAN
/interface bridge vlan
add bridge=bridge comment=secure-network tagged="sfp-sfpplus1-vlan-trunk -> CCR-1036,sfp-sfpplus2-vlan-trunk -> CRS-326" untagged=ether1-secure,ether2-secure,ether3-secure,ether4-secure,ether5-secure,ether6-secure,ether7-secure,ether8-secure \
vlan-ids=100
add bridge=bridge comment=unsecure-network tagged="sfp-sfpplus1-vlan-trunk -> CCR-1036,sfp-sfpplus2-vlan-trunk -> CRS-326" untagged=\
ether9-unsecure,ether10-unsecure,ether11-unsecure,ether12-unsecure,ether13-unsecure,ether14-unsecure,ether15-unsecure,ether16-unsecure vlan-ids=110
add bridge=bridge comment=synology-survey tagged="sfp-sfpplus1-vlan-trunk -> CCR-1036,sfp-sfpplus2-vlan-trunk -> CRS-326" untagged=\
ether19-synology-survey,ether20-synology-survey,ether21-synology-survey,ether22-synology-survey,ether23-synology-survey vlan-ids=120
/interface list member
add interface=bridge list=VLAN
/ip address
add address=10.10.99.2/24 comment=defconf interface=bridge network=10.10.99.0
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/system routerboard settings
set boot-os=router-os