I have another question, I am overlooking something very simple I guess.
I’ve set up my RB3011 with several VLANs. They are all connected to the network via trunk, which is linked to a port-aggregation (eth 4+5)
In parallel, I have eth10 acting as a management port (VLAN 2 - 172.20.2.0/24)
hosts in the vlan 2 can ping themselves, but can’t ping the MT Vlan2 interface (.10), nor can the MT ping any of these hosts in that directly connected network. As the network is directly connected, it can’t be a routing issue.
Even more interrestingly, I can reach the the vlan2 L3 IP from any of the other vlans (traffic ingress from LAG+trunk which does NOT contain VLAN2)
My config looks like this, I just cleaned up the stuff that is not relevant (GRE's, IPsec, disabled interfaces, etc):
The only clues I could think of would be some issue with the interface lists (VLAN2/interface eth10 is the only vlan in the MGT list), or the packets getting into the wrong chain.
# jun/30/2022 23:07:06 by RouterOS 7.3.1
# software id = GTSP-YUM6
#
# model = RB3011UiAS
/interface bridge
add name=loopback0
/interface ethernet
set [ find default-name=ether1 ] name=eth1-WAN
set [ find default-name=ether4 ] name="eth4 - Transit LAG 10"
set [ find default-name=ether5 ] name="eth5 - Transit LAG 10"
set [ find default-name=ether10 ] name="eth10 - MGT" poe-out=off
/interface vlan
add interface="eth10 - MGT" name="vlan2 - MGT" vlan-id=2
add interface=ether8 name="vlan51 - VLAN0051" vlan-id=51
add interface=eth1-WAN loop-protect=off name="vlan4001 - ISP WAN" vlan-id=4001
/interface bonding
add arp-ip-targets=0.0.0.0 lacp-rate=1sec mode=802.3ad name=LAG10 slaves="eth4 - Transit LAG 10,eth5 - Transit LAG 10"
/interface vlan
add interface=LAG10 name="vlan10 - SERVER-PRIVATE" vlan-id=10
add interface=LAG10 name="vlan15 - SERVER-PUBLIC" vlan-id=15
add interface=LAG10 name="vlan20 - WORKSTATIONS" vlan-id=20
add interface=LAG10 name="vlan30 - IPTEL" vlan-id=30
add interface=LAG10 name="vlan40 - PRINTERS" vlan-id=40
add interface=LAG10 name="vlan50 - LAB" vlan-id=50
add interface=LAG10 name="vlan60 - WLAN" vlan-id=60
add interface=LAG10 name="vlan100 - TRANSIT" vlan-id=100
/interface list
add comment=defconf name=WAN
add comment=TRANSIT name=TRANSIT
add comment="Out-of-Band Management" name=MGT
/interface bridge port
add bridge=*E ingress-filtering=no interface=*D
/ip firewall connection tracking
set enabled=yes
/ip neighbor discovery-settings
set discover-interface-list=all
/interface list member
add comment="WAN - Public Fiber" interface=eth1-WAN list=WAN
add comment="Management Interface" interface="eth10 - MGT" list=MGT
add comment=Transit interface=LAG10 list=TRANSIT
/ip address
add address=172.20.2.10/24 comment=Management interface="eth10 - MGT" network=172.20.2.0
add address=172.20.100.254/24 comment="Transit vlan 100" interface="vlan100 - TRANSIT" network=172.20.100.0
add address=172.20.10.1/24 comment=SERVER-PRIVATE interface="vlan10 - SERVER-PRIVATE" network=172.20.10.0
add address=172.20.20.1/24 comment=WORKSTATIONS interface="vlan20 - WORKSTATIONS" network=172.20.20.0
add address=172.20.30.1/24 comment=IPTEL interface="vlan30 - IPTEL" network=172.20.30.0
add address=172.20.40.1/24 comment=PRINTER interface="vlan40 - PRINTERS" network=172.20.40.0
add address=172.20.50.1/24 comment=LAB interface="vlan50 - LAB" network=172.20.50.0
add address=172.20.60.1/24 comment=WLAN interface="vlan60 - WLAN" network=172.20.60.0
add address=172.20.0.1 interface=loopback0 network=172.20.0.1
/ip firewall address-list
add address=172.20.20.0/24 list=NAT
add address=172.20.60.0/24 list=NAT
/ip firewall filter
add action=accept chain=input dst-address=172.20.2.0/24 src-address=172.16.0.0/12
add action=accept chain=output dst-address=172.16.0.0/12 src-address=172.20.2.0/24
(...)
/ip firewall nat
add action=masquerade chain=srcnat dst-address=!172.16.0.0/12 out-interface=pppoe-WAN src-address=172.20.0.0/16
When I torch the interface eth10, I see incoming packets from the host in the 172.20.2.0/24 segment I am initiating the icmp packets from.
Does any of you have an idea what the cause could be?
Cheers
Denis