Tak jsem dlouho nepsal ale mám tu další výzvu kterou nemůžu vygooglit.
Mám hlavní Router hAP ac². Na ETH1 je wan.
Router funguje tak jak má jen potřebuju aby ETH2 tagoval do vlan2 ale zároveň na něm běžel dhcp aby dostal ipadresu (potřebuju se tam dostat do nastavení modemu ale net z něj nepotřebuju).
No a tu vlan1 a vlan2 posílal do ETH4 (už vím že musím být Trunk).
No a za ETH4 bude druhej mikrotik kterej rozdělí vlan1 do ETH1+2 a vlan2 do ETH3+4 a hlavně do ETH5 zase obě vlany.
Pro ukázku stávající config, děkuji...
PS: Nastavuju ve winboxu.
# jun/12/2019 01:43:47 by RouterOS 6.44.3
# software id = LUHJ-J593
#
# model = RouterBOARD D52G-5HacD2HnD-TC
# serial number = 92F208CA06F6
/interface bridge
add admin-mac=CC:2D:E0:EB:8F:10 auto-mac=no comment=defconf name=bridge
add name=bridge-Pavsax
/interface wireless
set [ find default-name=wlan1 ] antenna-gain=3 band=2ghz-g/n channel-width=\
20/40mhz-Ce country="czech republic" disabled=no distance=indoors \
frequency=auto frequency-mode=regulatory-domain hide-ssid=yes mode=\
ap-bridge radio-name="RDan 2,4ghz" ssid=RDan wireless-protocol=802.11 \
wps-mode=disabled
set [ find default-name=wlan2 ] antenna-gain=3 band=5ghz-a/n/ac \
channel-width=20/40mhz-Ce country="czech republic" disabled=no distance=\
indoors frequency=auto frequency-mode=regulatory-domain hide-ssid=yes \
mode=ap-bridge radio-name="RDan 5ghz" ssid=RDan wireless-protocol=802.11 \
wps-mode=disabled
/interface vlan
add interface=ether1 name="vlan VDSL" vlan-id=848
add interface=ether1 name=vlan-modem vlan-id=1
/interface pppoe-client
add add-default-route=yes disabled=no interface="vlan VDSL" name=365internet \
password=365internet use-peer-dns=yes user=365internet
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" \
mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=\
***** wpa2-pre-shared-key=****
add authentication-types=wpa-psk,wpa2-psk eap-methods="" mode=dynamic-keys \
name=profile supplicant-identity=MikroTik wpa-pre-shared-key=*****\
wpa2-pre-shared-key=*****
/interface wireless
add disabled=no mac-address=CE:2D:E0:EB:8F:15 master-interface=wlan2 name=\
wlan3 security-profile=profile ssid=RDan-prizivnici wps-mode=disabled
add disabled=no mac-address=CE:2D:E0:EB:8F:14 master-interface=wlan1 name=\
wlan4 security-profile=profile ssid=RDan-prizivnici wps-mode=disabled
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=dhcp ranges=10.111.111.10-10.111.111.250
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge lease-time=12h name=\
defconf
/interface bridge filter
add action=drop chain=forward in-interface=wlan3
add action=drop chain=forward out-interface=wlan3
add action=drop chain=forward in-interface=wlan4
add action=drop chain=forward out-interface=wlan4
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2
add bridge=bridge interface=wlan3
add bridge=bridge interface=wlan4
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface bridge vlan
add bridge=bridge vlan-ids=1
add bridge=bridge-Pavsax tagged=bridge-Pavsax vlan-ids=2
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=365internet list=WAN
/ip address
add address=10.111.111.1/24 comment=defconf interface=ether2 network=\
10.111.111.0
add address=192.168.1.2/24 interface=ether1 network=192.168.1.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=bridge-Pavsax
/ip dhcp-server lease
add address=10.111.111.30 client-id=1:50:e5:49:b2:31:2e \
mac-address=50:E5:49:B2:31:2E server=defconf
add address=10.111.111.90 mac-address=B0:46:FC:9E:80:4B \
server=defconf
add address=10.111.111.20 client-id=1:9c:5c:8e:90:69:4d \
mac-address=9C:5C:8E:90:69:4D server=defconf
add address=10.111.111.40 client-id=1:c4:17:fe:9:9e:7e \
mac-address=C4:17:FE:09:9E:7E server=defconf
add address=10.111.111.80 client-id=1:d4:38:9c:88:eb:a4 \
mac-address=D4:38:9C:88:EB:A4 server=defconf
add address=10.111.111.251 client-id=1:flag_cc:2d:e0:25:62:a9 \
mac-address=CE:2D:E0:25:62:AA server=defconf
add address=10.111.111.70 client-id=1:b4:52:7d:57:f0:5c \
mac-address=B4:52:7D:57:F0:5C server=defconf
add address=10.111.111.60 client-id=1:5c:9a:d8:62:2c:69 \
mac-address=5C:9A:D8:62:2C:69 server=defconf
add address=10.111.111.100 mac-address=4C:12:65:BE:9C:21 \
server=defconf
add address=10.111.111.3 client-id=1:74:4d:28:48:53:41 mac-address=\
74:4D:28:48:53:41 server=defconf
/ip dhcp-server network
add address=10.111.111.0/24 comment=defconf gateway=10.111.111.1 ntp-server=\
217.31.202.100
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=10.111.111.1 name=router.lan
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment=PF dst-port=49619 in-interface=\
365internet protocol=tcp to-addresses=10.111.111.2 to-ports=49619
add action=dst-nat chain=dstnat comment=PF dst-port=49619 in-interface=\
365internet protocol=udp to-addresses=10.111.111.2 to-ports=49619
/ip service
set telnet disabled=yes
set ftp disabled=yes
set ssh disabled=yes
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=bridge type=internal
add interface=365internet type=external
add type=external
/system clock
set time-zone-name=Europe/Prague
/system identity
set name=RDan-MikroTik
/system ntp client
set enabled=yes primary-ntp=217.31.202.100 secondary-ntp=195.113.144.201
/tool graphing interface
add
/tool graphing resource
add
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
A ještě mě napadla taková čistě praktická blbost. Dle logu se vždy snaží připojit k pppoe dřív než se začne switch. Nejde to někde jednoduše poladit? Je to jen taková kravinka :)