Community discussions

MikroTik App
 
danielwinn
just joined
Topic Author
Posts: 1
Joined: Mon May 27, 2024 11:39 am

Beginner's question: Bridging and VLANs

Mon May 27, 2024 11:41 am

Hey there, I have running a MikroTik-hEX and a CRS328-24P-4S+ and the latest LTE versions of RouterOS respectively SwitchOS.

So far I am not doing anything fancslopey with the setup: a Unifi AP is connected to the switch as well as a couple of ethernet sockets, but all of them have no VLAN tags or any separation at all. Even the three SSIDs of the AP are running on the same network so far.

My target, though, is to have a setup of 9 VLANs to separate admin, smart home (mainly Shellys) and personal devices as well as work devices (Home Office).

I started reading some tutorials about setting up VLANs in RouterOS, but what I don't quite understand yet is, what to do with bridges. Would I put all networks
  • on one bridge
  • on two bridges: on with internet access and one without
  • on even more bridges
or would I to the rules on which traffic is allowed inbetween the networks with firewall rules?

Thanks a lot for some hints in form of posts or links!

cheers :-)
 
tdw
Forum Guru
Forum Guru
Posts: 1906
Joined: Sat May 05, 2018 11:55 am

Re: Beginner's question: Bridging and VLANs

Mon May 27, 2024 1:53 pm

One bridge. See viewtopic.php?t=143620, viewtopic.php?t=173692, https://help.mikrotik.com/docs/display/ ... upExamples for RouterOS, https://help.mikrotik.com/docs/pages/vi ... ionExample for SwOS.

The bridge and VLANs segregate the layer 2 / ethernet networks, by default layer 3 / IP packets are forwarded between networks unless you have firewall rules to restrict them.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 20026
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Beginner's question: Bridging and VLANs

Mon May 27, 2024 3:59 pm

If you are sticking with UNIFI smart APs, keep in mind you will need to connect to them via a HYBRID PORT.
The management or Trusted VLAN ( the one where it gets its IP address from) is expected to arrive at the UNIFI untagged and the rest of the vlans tagged.

Who is online

Users browsing this forum: Bing [Bot], ech1965, Fogga, GoogleOther [Bot] and 21 guests