So one thing that has perplexed me for a while now with Mikrotik is being able to easily segment the network.
All I want to achieve is to add a couple of extra SSIDs, with their own subnets and their own DHCP scopes, where I can filter traffic with the Firewall.
I have reviewed the following examples, and while they are useful, they tend to cover more than I need:
https://help.mikrotik.com/docs/display/ ... n+Wireless
viewtopic.php?f=13&t=143620&sid=4745b93 ... 51dd517cd4
I have just a single AX3 for the entire house so I don't really need to worry about trunking.
Ideally, I would like to add a new VLAN for the new SSID without messing with the existing config. I assume that defconf is in VLAN1, even though not explicitly stated. I know VLAN1 isn't best practice, but this is just my house, I'm not too concerned.
I have tried using the Guest Wireless option within Quick Set, but this adds bridge filters and shares IP space, and I'd rather control this with firewall rules and have each SSID associated with it's own /24 with DHCP.
Here is the key config I have now, exluding stuff like firewalls:
Code: Select all
/interface ethernet set [ find default-name=ether1 ] comment=WAN
/interface ethernet set [ find default-name=ether2 ] comment=Switch
/interface ethernet set [ find default-name=ether3 ] comment=Base
/interface wifi set [ find default-name=wifi1 ] channel.skip-dfs-channels=10min-cac configuration.mode=ap .ssid=HOME disabled=no security.authentication-types=wpa2-psk,wpa3-psk
/interface wifi set [ find default-name=wifi2 ] channel.skip-dfs-channels=10min-cac configuration.mode=ap .ssid=HOME disabled=no security.authentication-types=wpa2-psk,wpa3-psk
/interface list add comment=defconf name=WAN
/interface list add comment=defconf name=LAN
/ip pool add name=dhcp ranges=192.168.1.30-192.168.1.200
/ip dhcp-server add address-pool=dhcp interface=bridge lease-time=23h59m59s name=defconf
/interface bridge port add bridge=bridge comment=defconf interface=ether2 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=bridge comment=defconf interface=ether3 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=bridge comment=defconf interface=ether4 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=bridge comment=defconf interface=ether5 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=bridge comment=defconf interface=wifi1 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=bridge comment=defconf interface=wifi2 internal-path-cost=10 path-cost=10
/interface list member add comment=defconf interface=bridge list=LAN
/interface list member add comment=defconf interface=ether1 list=WAN
/interface list member add interface=pppoe-out1 list=WAN
/ip address add address=192.168.1.254/24 comment=defconf interface=bridge network=192.168.1.0
/ip dhcp-server network add address=192.168.1.0/24 comment=defconf dns-server=192.168.1.2 gateway=192.168.1.254 netmask=24
Losing WiFi access would be a PITA to then resolve so I will be sure to use safe mode..
Thank you!