Ahojte

trapim sa s nasledovnou konfiguraciou, vlan na switchy co si zakaznik kupil. CRS112-8P-4S

Na switchy su zapojené porty nasledovne

port 2 - TRUNK_Uplink to cisco 2960

port 4 - Vlan221 access

port 7 - (WIFI AP R310) Trunk (Vlan 222-224) native Vlan 221 access

port 8 - (WIFI AP R310) Trunk (Vlan 222-224) native Vlan 221 access

Zapojené to je nasledovne

Hlavny router ==(Trunk221-224)== SW CISCO ==(Trunk221-224)== SW CRS112

Moja konfiguracia je nasledovná:

/interface bridge

add name=Switch_Vlan

/interface bridge port

add bridge=Switch_Vlan interface=ether2 hw=yes

add bridge=Switch_Vlan interface=ether4 hw=yes

add bridge=Switch_Vlan interface=ether7 hw=yes

add bridge=Switch_Vlan interface=ether8 hw=yes

/interface ethernet switch ingress-vlan-translationadd ports=ether4,ether7,ether8 customer-vid=0 new-customer-vid=221

/interface ethernet switch egress-vlan-tag

add tagged-ports=ether2 vlan-id=221

add tagged-ports=ether2,ether7,ether8 vlan-id=222

add tagged-ports=ether2,ether7,ether8 vlan-id=223

add tagged-ports=ether2,ether7,ether8 vlan-id=224

/interface ethernet switch vlan

add ports=ether2,ether4,ether7,ether8 vlan-id=221 learn=yes

add ports=ether2,ether4,ether7,ether8 vlan-id=222 learn=yes

add ports=ether2,ether4,ether7,ether8 vlan-id=223 learn=yes

add ports=ether2,ether4,ether7,ether8 vlan-id=224 learn=yes

/interface ethernet switch

set drop-if-invalid-or-src-port-not-member-of-vlan-on-ports=ether2,ether4,ether7,ether8

Skusal som priradit IP k vlan 221 ktorá je ako managment ale najak sa mi nedari aby to prechadzalo

/interface vlan

add interface=Switch_Vlan name=MGMT vlan-id=221

/ip address

add address=10.100.1.3/24 interface=MGMT

Kde robim chybu ? preco mi to neprechádza ?

Dakujem za kazdu radu

Michal

Skusal som to stym aj bez toho výsledok je rovnaký

na wiki mikrotkiku je to ako bez switch_cpu.

o 2 roky později

Ahoj všem,

řeším teď jeden problém u těchto SW.
Nasadil jsem je pouze jako SW + několik VLAN..
Datový tok je cca 20Mbps a CPU lítá okolo 30%.
RouterOS je 6.48

/interface bridge
add name=local pvid=100 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment=Uplink disabled=yes poe-out=off
set [ find default-name=ether2 ] comment=CAM1
set [ find default-name=ether3 ] comment=CAM2
set [ find default-name=ether4 ] comment=CAM3
set [ find default-name=ether5 ] comment=CAM4
set [ find default-name=ether6 ] comment=CAM5
set [ find default-name=ether7 ] comment=CAM6
set [ find default-name=ether8 ] comment=Servis
set [ find default-name=sfp9 ] advertise="10M-half,10M-full,100M-half,100M-ful\
l,1000M-half,1000M-full,2500M-full,5000M-full,10000M-full" comment=\
"Optika SW2"
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=local interface=ether1
add bridge=local interface=ether2 pvid=210
add bridge=local interface=ether3 pvid=210
add bridge=local interface=ether4 pvid=210
add bridge=local interface=ether5 pvid=210
add bridge=local interface=ether6 pvid=3001
add bridge=local interface=ether7 pvid=3001
add bridge=local interface=ether8 pvid=100
add bridge=local interface=sfp9
/ip neighbor discovery-settings
set discover-interface-list=all
/interface bridge vlan
add bridge=local tagged=ether1,sfp9 untagged=ether8,local vlan-ids=100
add bridge=local tagged=ether1,sfp9 untagged=ether2,ether3,ether4,ether5 \
vlan-ids=210
add bridge=local tagged=ether1,sfp9 untagged=ether6,ether7 vlan-ids=3001
/ip address
add address=172.20.29.22/24 interface=local network=172.20.29.0
/ip firewall service-port
set sip disabled=yes
/system clock
set time-zone-name=Europe/Prague
/system identity
set name=SW_CAM
/system ntp client
set enabled=yes primary-ntp=172.20.29.1

Jestli ti jde o CPU, tak je to normální chování. Mě tam teče lehce přes 100Mbit, jsou tam 3 VLANy, (přes switch, ne CPU) a občas je tam i přes 50%. Na funkci přepínání to nemá vliv.

📡 Telekomunikace.cz