Community discussions

MikroTik App
 
devtomas2003
just joined
Topic Author
Posts: 1
Joined: Mon May 07, 2018 8:15 pm

Problems with VLANs

Thu Nov 19, 2020 4:06 pm

Hello, I have a problem. I have a router, with 3 interfaces, one connected to the internet, another connected to a radius and another connected to a switch, on that same router, I have a fixed port connected to vlan 14 which is the "Rede Administrativa" for the radius, this router creates the vlans and injects DHCP into each one. On the switch, I have 2 interfaces, one coming from the router and the other connected to a client, on that same switch I have the dot1x protocol configured and working beautifully on practically all networks except on vlan 14. On the Router, a status of DHCP Releases appears IP offered but not bound. Attached I send the settings.

Image

Switch:

/interface bridge
add name=Redes vlan-filtering=yes
/interface ethernet
set [ find default-name=ether2 ] name=Cliente
set [ find default-name=ether1 ] name=UpLink
/interface vlan
add interface=UpLink name="Rede Admin" vlan-id=14
/interface bridge port
add bridge=Redes interface=UpLink
add bridge=Redes interface=Cliente
/interface bridge vlan
add bridge=Redes tagged=UpLink vlan-ids=10
add bridge=Redes tagged=UpLink vlan-ids=11
add bridge=Redes tagged=UpLink vlan-ids=12
add bridge=Redes tagged=UpLink vlan-ids=13
add bridge=Redes tagged=UpLink vlan-ids=14
add bridge=Redes tagged=UpLink vlan-ids=15
add bridge=Redes tagged=UpLink vlan-ids=16
/interface dot1x server
add interface=Cliente reject-vlan-id=16
/ip address
add address=10.20.178.5/24 interface="Rede Admin" network=10.20.178.0
/radius
add address=10.20.178.2 realm=viriato.edu secret=Olamundo2003 service=dot1x
/system identity
set name=swViseu
/tool romon
set enabled=yes id=00:00:00:00:00:07 secrets=immtelecom

Router:

/interface bridge
add name=Admins-Conectividade
add name=Switches
/interface ethernet
set [ find default-name=ether3 ] name=Radius
set [ find default-name=ether2 ] name=SW
set [ find default-name=ether1 ] name=UpLink
/interface vlan
add interface=Switches name="Rede AO" vlan-id=12
add interface=Switches name="Rede Administrativa" vlan-id=14
add interface=Switches name="Rede Alunos" vlan-id=10
add interface=Switches name="Rede Profs" vlan-id=11
add interface=Switches name="Rede Quarentena" vlan-id=16
add interface=Switches name="Rede Salas TIC" vlan-id=13
add interface=Switches name="Rede Visitantes" vlan-id=15
/ip pool
add name=dhcp_pool0 ranges=10.20.178.10-10.20.178.254
add name=dhcp_pool1 ranges=10.3.0.2-10.3.0.254
add name=dhcp_pool2 ranges=10.1.0.2-10.1.15.254
add name=dhcp_pool3 ranges=10.4.0.2-10.4.1.254
add name=dhcp_pool4 ranges=10.6.0.2-10.6.0.254
add name=dhcp_pool5 ranges=10.2.0.2-10.2.3.254
add name=dhcp_pool6 ranges=10.5.0.2-10.5.1.254
/ip dhcp-server
add address-pool=dhcp_pool0 disabled=no interface=Admins-Conectividade name=\
dhcp1
add address-pool=dhcp_pool1 disabled=no interface="Rede AO" name=dhcp2
add address-pool=dhcp_pool2 disabled=no interface="Rede Alunos" name=dhcp3
add address-pool=dhcp_pool3 disabled=no interface="Rede Profs" name=dhcp4
add address-pool=dhcp_pool4 disabled=no interface="Rede Quarentena" name=\
dhcp5
add address-pool=dhcp_pool5 disabled=no interface="Rede Salas TIC" name=dhcp6
add address-pool=dhcp_pool6 disabled=no interface="Rede Visitantes" name=\
dhcp7
/interface pppoe-client
add add-default-route=yes allow=mschap1,mschap2 disabled=no interface=UpLink \
name="Autentica\E7\E3o NSO" password=viriato profile=default-encryption \
user=viriato
/interface bridge port
add bridge=Switches interface=SW
add bridge=Admins-Conectividade interface=Radius
add bridge=Admins-Conectividade interface="Rede Administrativa"
/ip address
add address=10.20.178.1/24 interface="Rede Administrativa" network=\
10.20.178.0
add address=10.3.0.1/24 interface="Rede AO" network=10.3.0.0
add address=10.1.0.1/20 interface="Rede Alunos" network=10.1.0.0
add address=10.4.0.1/23 interface="Rede Profs" network=10.4.0.0
add address=10.6.0.1/24 interface="Rede Quarentena" network=10.6.0.0
add address=10.2.0.1/22 interface="Rede Salas TIC" network=10.2.0.0
add address=10.5.0.1/23 interface="Rede Visitantes" network=10.5.0.0
/ip dhcp-server network
add address=10.1.0.0/20 dns-server=10.1.0.1 domain=alunos.viriato gateway=\
10.1.0.1
add address=10.2.0.0/22 dns-server=10.2.0.1 domain=salastic.viriato gateway=\
10.2.0.1
add address=10.3.0.0/24 dns-server=10.3.0.1 domain=ao.viriato gateway=\
10.3.0.1
add address=10.4.0.0/23 dns-server=10.4.0.1 domain=profs.viriato gateway=\
10.4.0.1
add address=10.5.0.0/23 dns-server=10.5.0.1 domain=visitantes.viriato \
gateway=10.5.0.1
add address=10.6.0.0/24 dns-server=10.6.0.1 domain=quarentena.viriato \
gateway=10.6.0.1
add address=10.20.178.0/24 dns-server=10.20.178.2 domain=admin.viriato \
gateway=10.20.178.1
/ip dns
set allow-remote-requests=yes servers=10.20.178.2
/ip firewall nat
add action=masquerade chain=srcnat out-interface="Autentica\E7\E3o NSO"
add action=dst-nat chain=dstnat dst-port=1812 in-interface=\
"Autentica\E7\E3o NSO" protocol=udp to-addresses=10.20.178.2 to-ports=\
1812
/system identity
set name=ViriatoRouter
/tool romon
set enabled=yes id=00:00:00:00:00:04 secrets=immtelecom

Who is online

Users browsing this forum: anav, Baidu [Spider], robmaltsystems and 93 guests