Quantcast
Channel: MikroTik
Viewing all articles
Browse latest Browse all 21093

General • Re: Confused about VLANs

$
0
0
Yes, there are things to be done in different places and, when one gets very intimate with ROS VLAN, it all makes sense. Because ROS allows you to do things others don't (whether that makes sense or not is a completely different thing).

As a rule of thumb: bridge/port section is about ingress properties while bridge/vlan is about egress properties (things can get tied with ingress-filtering=yes).
So it is, for example, possible to set certain port as untagged member of some VLAN but set pvid to different value. Meaning that port can be untagged member of several VLANs for egress (for ingress it can only be access port of a single VLAN).
And this might be useful if some VLAN carries e.g. broadcast streams and there's a client beyond a bridge port that is supposed to receive those broadcasts ... but duplex communication is not needed (or wanted).
I'm struggling to understand the example you provided but, I guess, for my use case, it's not really needed.

Actually for now I'm configuring the CRS317 but should be similar ...

Right now I don't even have a "stable" definition of ports, so by default:
- All Ports Untagged to a "Default" VLANs
- All Ports Tagged to all Required VLANs (all are basically trunks)

Then I'll do the required VLAN setup either in a Hypervisor (Proxmox VE) or a GNU/Linux Computer or SBC.

I added a new IP Address for the Router OS Switch in IP -> Addresses: 192.168.150.71/22 with Network 192.168.148.0 for Interface "bridge". However, I cannot ping it from my local PC (tried both on eno1.100 which was VLAN Tagged 192.168.148.6 and eno1 which was untagged 192.168.148.12). I also weirdly cannot ping between Router OS Switches with their new .71 / .72 / .73 address.
I plan to always leave a port to NOT require any management VLAN on ether1 (unused by default) in case I need to rescue the installation.

But why are the new IP address not accessible ? Do I need to reboot the Switch for changes to take effect :shock: ?

EDIT: it actually works if I do a ifconfig eno1.100 down, since VLAN filtering is not yet enabled

Statistics: Posted by luckylinux — Sun Dec 17, 2023 8:51 am



Viewing all articles
Browse latest Browse all 21093

Trending Articles