I'd like the MikroTik to act as a switch but to only allow traffic with VLAN ID 3 set. Normally I think you'd do this on the Unifi switch connected to the MikroTik device. It's a cheap Flex Mini, however, and doesn't support configuring assigning individual ports to a VLAN.
Requirements: all traffic into the hEX S's ethernet port 1 from the Unifi switch must be tagged with ID 3 and then untagged (I think this is done at the bridge level). All traffic out of the ethernet port 1 should have ID 3 tagged.
I've looked at the docs and hammered out the below configuration. Is there a better way to do this? Am I doing anything unnecessary? Thanks.
Code: Select all
/interface bridge
add name=bridge
/interface vlan
add interface=ether1 name=vlan3 vlan-id=3
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge frame-types=admit-only-vlan-tagged interface=vlan3
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=ether2 pvid=3
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=ether3 pvid=3
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=ether4 pvid=3
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=ether5 pvid=3
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface bridge vlan
add bridge=bridge tagged=vlan3 vlan-ids=3
/ip dhcp-client
add disabled=no interface=bridge
/system clock
set time-zone-name=Europe/London