Community discussions

MikroTik App
 
cracyfloyd
just joined
Topic Author
Posts: 4
Joined: Sun Jan 09, 2022 8:21 pm

mqtt from vlan10 to vlan1 (shelly, tasmota, iobroker, homekit)

Tue Jan 11, 2022 12:37 pm

which rule i need for my RB5009 that i can forward all mqtt requests (shelly port 1885, tasmota port 1883) which are in VLAN10 and my IOBroker (MQTT Server) are in VLAN1.
Or my other possibility is that the IOBroker are in VLAN10 too but then i have problems with my yahka (Homebridge) interface in IOBroker. when i try this in this way my iphones and ipads dont see this instanz. The iphones and ipads are in vlan1.
iam a realy beginner with mikrotik routers, so maybe its give an other way.


Thnx for answers
 
User avatar
Hominidae
Member
Member
Posts: 309
Joined: Thu Oct 19, 2017 12:50 am

Re: mqtt from vlan10 to vlan1 (shelly, tasmota, iobroker, homekit)

Thu Jan 13, 2022 4:49 pm

Basically the inter VLAN routing should be enabled per default.
Hence, the "normal" way of doing what you want is not to enable forwarding but rather to actually restrict the inter-VLAN routing between VL10 and VL1 to traffic/connections originating from VL10 to the mqtt Broker (IP and ports) on VL1 (drop all others).
This will still allow connection from VL1 to VL10 (i.e. for administration of your shelly or tasmota devices).

What you should see in the filter rules in the forwarding chain on your device should reveal a pattern.
- They should allow for already established connections between all local networks
- and allow for all connections on LAN (or rather everything that is not WAN - hence you should add your VLANs to the "LAN" interface list).
Place your new rule between these two.
See also: https://help.mikrotik.com/docs/display/ ... t+Firewall

Who is online

Users browsing this forum: No registered users and 17 guests