My problem is that when I turn on egress tagging the VLAN traffic from the Access point it filtered out (but untagged works - which I want), but my Interface port 3 traffic gets tagged correctly. But when I turn it egress tagging my Access Point has all traffic (both tagged and untagged) but my interface port tagging does not work.
On this switch, Trunk port is SFP9, I want port 3 tagged with VLAN ID 20, and I want the access point to transmit and receive VLAN ID 20 & 30, as well as untagged.
Any help would be greatly appreciated.
You can see below that /interface ethernet switch egress-vlan-tag
has the rule "add disabled=yes tagged-ports=sfp9 vlan-id=20" - which I causes the above problem.
Code: Select all
# nov/22/2022 18:45:11 by RouterOS 6.49.6
# software id = DXMK-IZJY
#
# model = CRS112-8P-4S
# serial number = HCB*******
/interface bridge
add admin-mac=DC:2C:6E:E6:47:9E auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether2 ] advertise=10M-half,10M-full,100M-half,100M-full poe-out=forced-on speed=100Mbps
set [ find default-name=ether3 ] poe-out=off
set [ find default-name=ether5 ] disabled=yes
set [ find default-name=ether6 ] disabled=yes
set [ find default-name=ether7 ] disabled=yes
set [ find default-name=ether8 ] disabled=yes
set [ find default-name=sfp9 ] advertise=1000M-full auto-negotiation=no
set [ find default-name=sfp10 ] auto-negotiation=no rx-flow-control=auto tx-flow-control=auto
set [ find default-name=sfp11 ] disabled=yes
set [ find default-name=sfp12 ] disabled=yes
/interface vlan
add interface=bridge name=vlan20 vlan-id=20
add interface=bridge name="vlan30 Guest" vlan-id=30
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge comment=defconf interface=ether1
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=sfp9
add bridge=bridge comment=defconf interface=sfp10
add bridge=bridge comment=defconf interface=sfp11
add bridge=bridge comment=defconf interface=sfp12
/interface bridge vlan
add bridge=bridge disabled=yes vlan-ids=1-4094
/interface ethernet switch egress-vlan-tag
add disabled=yes tagged-ports=sfp9 vlan-id=20
add disabled=yes tagged-ports=sfp9 vlan-id=30
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=20 ports=ether3,ether4
/interface ethernet switch mac-based-vlan
add new-customer-vid=20 src-mac-address=00:40:AD:BD:43:63
/interface ethernet switch port
set 1 egress-vlan-tag-table-lookup-key=according-to-bridge-type
set 2 allow-fdb-based-vlan-translate=yes
/interface ethernet switch vlan
add disabled=yes ports=ether3 vlan-id=20
/interface list member
add interface=ether1 list=LAN
add interface=ether2 list=LAN
add interface=ether3 list=LAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=ether6 list=LAN
add interface=ether7 list=LAN
add interface=ether8 list=LAN
add interface=sfp9 list=LAN
add interface=sfp10 list=LAN
add interface=sfp11 list=LAN
add interface=sfp12 list=LAN