Community discussions

MikroTik App
 
mitay3
just joined
Topic Author
Posts: 2
Joined: Tue May 03, 2011 10:48 am

ip unnumbered(vlan-per-user)

Thu May 05, 2011 5:19 am

Hello
how to implement the scheme vlan-per-user on mikrotik 3.20 with ip unnumbered?.

komp ----- cisco2950 trunk ------ ether1 mikrotik ether2 ----- internet

in the trunk are vlan11-13 on mikrotik created vlan11-13 at ether1. vlan11-13 added to bridge1. bridge1 address is 10.10.10.2/24, komp address is 10.10.10.3/24.
the problem is that komp not ping bridge1 if bridge1 included more than one vlan.

what am I doing wrong?
how to properly configure the mikrotik?
 
User avatar
enk
Member Candidate
Member Candidate
Posts: 165
Joined: Fri Aug 17, 2007 8:59 am
Location: Russia
Contact:

Re: ip unnumbered(vlan-per-user)

Thu May 05, 2011 1:07 pm

Hello
how to implement the scheme vlan-per-user on mikrotik 3.20 with ip unnumbered?.

komp ----- cisco2950 trunk ------ ether1 mikrotik ether2 ----- internet

in the trunk are vlan11-13 on mikrotik created vlan11-13 at ether1. vlan11-13 added to bridge1. bridge1 address is 10.10.10.2/24, komp address is 10.10.10.3/24.
the problem is that komp not ping bridge1 if bridge1 included more than one vlan.

what am I doing wrong?
how to properly configure the mikrotik?
If you have 3550 or higher (newer) switch, you will be able to configure private-vlans. On 2950 there is no such feature, so you can use one vlan for all users, but configure "switchport protected". Look at this documentation:
http://www.cisco.com/en/US/docs/switche ... #wp1158863
 
mitay3
just joined
Topic Author
Posts: 2
Joined: Tue May 03, 2011 10:48 am

Re: ip unnumbered(vlan-per-user)

Fri May 06, 2011 4:44 am

Thank you.
but it was in STP.
STP disabled and it worked
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: ip unnumbered(vlan-per-user)

Fri May 06, 2011 6:25 am

Turning off spanning tree in a switching/bridging environment is almost always a very bad idea.
Bridging three VLANs into one another is also almost always a very bad idea.

I see nothing in your (admittedly short) post that indicates any of the scenarios where either isn't a very bad idea, so you should possibly consider revisiting your network layout.

Who is online

Users browsing this forum: No registered users and 102 guests