I'm reasonably new to Mikrotik, however, I have a Mikrotik RB2011 as my home router for the past year or so.
I have recently gotten a CRS326-24G-2S+RM and I've been attempting to configure it with VLans. I have been beating my head against a wall on this. Can't quite figure it out. I think my issue relates to IP routing.
Anyways I have several VLANs and bridges set up along with a DHCP server, and when I connect a device to say my PCBridge I can a DHCP address and can ping the switch, HOWEVER, I have an Uplink bridge that connects to my Sophos XG firewall. I cannot ping that device, but I can from the switch.
Also, my "Uplink" VLAN can get to my firewall fine. Just no other VLAN and communicate or get to the firewall.
This is for home use so I like all my devices to communicate with one other; like my PC streaming to my Chromecast and my phone streaming to my Chromecast.
I have no idea where to go from here... Any help would be greatly appreciated. Heres my switch config:
Code: Select all
/interface bridge
add name=CamerasBridge
add name=PCBridge
add name=ServersBridge
add name=Uplink
add name=WAPsBridge
/interface ethernet
set [ find default-name=ether9 ] name="Cameras - Eth9"
set [ find default-name=ether10 ] name="Cameras - Eth10"
set [ find default-name=ether7 ] name=Cameras-Eth7
set [ find default-name=ether8 ] name=Cameras-Eth8
set [ find default-name=ether22 ] name="DNS - Eth22"
set [ find default-name=ether24 ] name=Eth24-Uplink
set [ find default-name=ether1 ] name=PC-Eth1
set [ find default-name=ether2 ] name=PC-Eth2
set [ find default-name=ether3 ] name=PC-Eth3
set [ find default-name=ether4 ] name=PC-Eth4
set [ find default-name=sfp-sfpplus1 ] name=SFP1-Uplink
set [ find default-name=sfp-sfpplus2 ] name=SFP2-Servers
set [ find default-name=ether14 ] name="WAPs - Eth14"
set [ find default-name=ether13 ] name="WAPs- Eth13"
set [ find default-name=ether5 ] disabled=yes
set [ find default-name=ether11 ] disabled=yes
set [ find default-name=ether12 ] disabled=yes
set [ find default-name=ether15 ] disabled=yes
set [ find default-name=ether16 ] disabled=yes
set [ find default-name=ether17 ] disabled=yes
set [ find default-name=ether18 ] disabled=yes
set [ find default-name=ether19 ] disabled=yes
set [ find default-name=ether20 ] disabled=yes
set [ find default-name=ether21 ] disabled=yes
set [ find default-name=ether23 ] disabled=yes
/interface vlan
add interface=Uplink name=VLAN10 vlan-id=10
add interface=Uplink name=VLAN20 vlan-id=20
add interface=Uplink name=VLAN30 vlan-id=30
add interface=Uplink name=VLAN40 vlan-id=40
add interface=Uplink name=VLAN50 vlan-id=50
/ip pool
add name=dhcp_pool0 ranges=10.10.50.2-10.10.50.254
add name=dhcp_pool1 ranges=10.10.50.2-10.10.50.254
add name=dhcp_pool2 ranges=10.10.10.10-10.10.10.20
add name=dhcp_pool3 ranges=10.10.30.2-10.10.30.254
add name=dhcp_pool4 ranges=10.10.20.2-10.10.20.254
add name=dhcp_pool5 ranges=10.10.40.2-10.10.40.254
/ip dhcp-server
add address-pool=dhcp_pool1 disabled=no interface=PCBridge name=dhcp1
add address-pool=dhcp_pool2 disabled=no interface=Uplink name=dhcp2
add address-pool=dhcp_pool3 disabled=no interface=CamerasBridge name=dhcp3
add address-pool=dhcp_pool4 disabled=no interface=ServersBridge name=dhcp4
add address-pool=dhcp_pool5 disabled=no interface=WAPsBridge name=dhcp5
/interface bridge port
add bridge=Uplink interface=Eth24-Uplink pvid=10
add bridge=PCBridge interface=PC-Eth2 pvid=50
add bridge=PCBridge interface=PC-Eth4 pvid=50
add bridge=PCBridge interface=PC-Eth1 pvid=50
add bridge=PCBridge interface=PC-Eth3 pvid=50
add bridge=CamerasBridge interface="Cameras - Eth9" pvid=30
add bridge=CamerasBridge interface="Cameras - Eth10" pvid=30
add bridge=CamerasBridge interface=Cameras-Eth7 pvid=30
add bridge=CamerasBridge interface=Cameras-Eth8 pvid=30
add bridge=WAPsBridge interface="WAPs - Eth14" pvid=40
add bridge=WAPsBridge interface="WAPs- Eth13" pvid=40
add bridge=ServersBridge interface="DNS - Eth22" pvid=20
add bridge=ServersBridge interface=SFP2-Servers pvid=20
add bridge=Uplink interface=ether6 pvid=10
add bridge=Uplink interface=SFP1-Uplink pvid=10
/interface bridge vlan
add bridge=Uplink tagged=Uplink untagged=\
CamerasBridge,PCBridge,ServersBridge,WAPsBridge vlan-ids=10
add bridge=CamerasBridge tagged=PCBridge,ServersBridge,WAPsBridge untagged=\
Uplink vlan-ids=30
add bridge=ServersBridge tagged=CamerasBridge,PCBridge,WAPsBridge untagged=\
Uplink vlan-ids=20
add bridge=WAPsBridge tagged=PCBridge untagged=Uplink vlan-ids=40
add bridge=PCBridge tagged=CamerasBridge,ServersBridge,WAPsBridge untagged=\
Uplink vlan-ids=50
/ip address
add address=10.10.10.2/24 interface=Uplink network=10.10.10.0
add address=10.10.50.1/24 interface=PCBridge network=10.10.50.0
add address=10.10.40.1/24 interface=WAPsBridge network=10.10.40.0
add address=10.10.30.1/24 interface=CamerasBridge network=10.10.30.0
add address=10.10.20.1/24 interface=ServersBridge network=10.10.20.0
/ip dhcp-server network
add address=10.10.10.0/24 gateway=10.10.10.1
add address=10.10.20.0/24 gateway=10.10.20.1
add address=10.10.30.0/24 gateway=10.10.30.1
add address=10.10.40.0/24 gateway=10.10.40.1
add address=10.10.50.0/24 gateway=10.10.50.1
/ip route
add distance=1 gateway=10.10.10.1
/system note
set note="10.10.10.1/24 pfSense\r\
\n10.10.10.2/24 router\r\
\n\r\
\n10.10.20.1/24 servers\r\
\n10.10.30.1/24 cameras\r\
\n10.10.40.1/24 waps\r\
\n10.10.50.1/24 pcs (mangement)"
/system routerboard settings
set boot-os=router-os
/tool romon
set enabled=yes