Мне нужна помощь с VLAN. У меня есть роутер с двумя VLAN: 50 (HOME) и 51 (Guests). Я использую CAPsMAN для управления двумя cAP AX и одним wAP ac. Один cAP AX подключён напрямую к RB4011, второй (и wAP ac) — через RB960PGS. Все устройства подключены через транковые порты (VLAN 50 и 51). Соответствующая конфигурация:
RB4011 # 2024-08-10 12:40:42, RouterOS 7.16rc1
# software id = 3EBJ-1MI6
# model = RB4011iGS+
# serial number = скрыт
/interface bridge
add admin-mac=скрыт auto-mac=no ingress-filtering=no name=bridge-LAN priority=0 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] disabled=yes
set [ find default-name=ether2 ] name=ether2-trunk-eetkamer
set [ find default-name=ether3 ] name=ether3-printer
set [ find default-name=ether4 ] name=ether4-nassie
set [ find default-name=ether5 ] name=ether5-nassie
set [ find default-name=ether6 ] name=ether6-solar
set [ find default-name=ether7 ] name=ether7-hue
set [ find default-name=ether8 ] name=ether8-tv-boven
set [ find default-name=ether9 ] name=ether9-trunk-woonkamer
set [ find default-name=ether10 ] name=ether10-ap-boven
set [ find default-name=sfp-sfpplus1 ] name=sfp1-WAN
/interface vlan
add interface=bridge-LAN name=GUEST_VLAN vlan-id=51
add interface=bridge-LAN name=HOME_VLAN vlan-id=50
/interface bridge port
add bridge=bridge-LAN interface=ether2-trunk-eetkamer internal-path-cost=10 path-cost=10
add bridge=bridge-LAN interface=ether3-printer internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether10-ap-boven internal-path-cost=10 path-cost=10
add bridge=bridge-LAN interface=ether7-hue internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether8-tv-boven internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=LCAP_DS1019+ internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether9-trunk-woonkamer internal-path-cost=10 path-cost=10
/interface bridge vlan
add bridge=bridge-LAN tagged=bridge-LAN,ether2-trunk-eetkamer,ether9-trunk-woonkamer,ether10-ap-boven untagged=ether3-printer,ether7-hue,ether8-tv-boven,LCAP_DS1019+ vlan-ids=50
add bridge=bridge-LAN tagged=bridge-LAN,ether2-trunk-eetkamer,ether9-trunk-woonkamer,ether10-ap-boven vlan-ids=51
/interface wifi capsman
set enabled=yes interfaces=bridge-LAN package-path=/packages require-peer-certificate=no upgrade-policy=none
RB960PGS # aug/10/2024 12:37:31 by RouterOS 6.49.13
# software id = R7TG-X42S
# model = 960PGS
# serial number = скрыт
/interface bridge
add admin-mac=скрыт auto-mac=no name=bridge-lan priority=0x4000
/interface ethernet
set [ find default-name=ether1 ] name=ether1-trunk
set [ find default-name=ether2 ] name=ether2-tv
set [ find default-name=ether3 ] name=ether3-nuc
set [ find default-name=ether4 ] name=ether4-amp
set [ find default-name=ether5 ] name=ether5-ap-beneden poe-out=forced-on
set [ find default-name=sfp1 ] disabled=yes
/interface ethernet switch port
set 0 vlan-mode=secure
set 1 default-vlan-id=50 vlan-mode=secure
set 2 default-vlan-id=50 vlan-mode=secure
set 3 default-vlan-id=50 vlan-mode=secure
set 4 vlan-mode=secure
set 5 vlan-mode=secure
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge-lan interface=ether1-trunk
add bridge=bridge-lan interface=ether2-tv
add bridge=bridge-lan interface=ether3-nuc
add bridge=bridge-lan interface=ether4-amp
add bridge=bridge-lan interface=ether5-ap-beneden
/ip neighbor discovery-settings
set discover-interface-list=all
/interface ethernet switch vlan
add independent-learning=no ports=ether1-trunk,ether2-tv,ether3-nuc,ether4-amp,ether5-ap-beneden switch=switch1 vlan-id=50
add independent-learning=no ports=ether1-trunk,ether5-ap-beneden switch=switch1 vlan-id=51
add independent-learning=yes ports=ether1-trunk,ether5-ap-beneden switch=switch1 vlan-id=1
Вопрос: На RB960PGS мне нужно добавить VLAN ID 1 (что логично) и включить independent-learning, чтобы управлять CAP. Это правильная настройка? Потому что на роутере я явно не использую VLAN ID 1.
RB4011 # 2024-08-10 12:40:42, RouterOS 7.16rc1
# software id = 3EBJ-1MI6
# model = RB4011iGS+
# serial number = скрыт
/interface bridge
add admin-mac=скрыт auto-mac=no ingress-filtering=no name=bridge-LAN priority=0 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] disabled=yes
set [ find default-name=ether2 ] name=ether2-trunk-eetkamer
set [ find default-name=ether3 ] name=ether3-printer
set [ find default-name=ether4 ] name=ether4-nassie
set [ find default-name=ether5 ] name=ether5-nassie
set [ find default-name=ether6 ] name=ether6-solar
set [ find default-name=ether7 ] name=ether7-hue
set [ find default-name=ether8 ] name=ether8-tv-boven
set [ find default-name=ether9 ] name=ether9-trunk-woonkamer
set [ find default-name=ether10 ] name=ether10-ap-boven
set [ find default-name=sfp-sfpplus1 ] name=sfp1-WAN
/interface vlan
add interface=bridge-LAN name=GUEST_VLAN vlan-id=51
add interface=bridge-LAN name=HOME_VLAN vlan-id=50
/interface bridge port
add bridge=bridge-LAN interface=ether2-trunk-eetkamer internal-path-cost=10 path-cost=10
add bridge=bridge-LAN interface=ether3-printer internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether10-ap-boven internal-path-cost=10 path-cost=10
add bridge=bridge-LAN interface=ether7-hue internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether8-tv-boven internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=LCAP_DS1019+ internal-path-cost=10 path-cost=10 pvid=50
add bridge=bridge-LAN interface=ether9-trunk-woonkamer internal-path-cost=10 path-cost=10
/interface bridge vlan
add bridge=bridge-LAN tagged=bridge-LAN,ether2-trunk-eetkamer,ether9-trunk-woonkamer,ether10-ap-boven untagged=ether3-printer,ether7-hue,ether8-tv-boven,LCAP_DS1019+ vlan-ids=50
add bridge=bridge-LAN tagged=bridge-LAN,ether2-trunk-eetkamer,ether9-trunk-woonkamer,ether10-ap-boven vlan-ids=51
/interface wifi capsman
set enabled=yes interfaces=bridge-LAN package-path=/packages require-peer-certificate=no upgrade-policy=none
RB960PGS # aug/10/2024 12:37:31 by RouterOS 6.49.13
# software id = R7TG-X42S
# model = 960PGS
# serial number = скрыт
/interface bridge
add admin-mac=скрыт auto-mac=no name=bridge-lan priority=0x4000
/interface ethernet
set [ find default-name=ether1 ] name=ether1-trunk
set [ find default-name=ether2 ] name=ether2-tv
set [ find default-name=ether3 ] name=ether3-nuc
set [ find default-name=ether4 ] name=ether4-amp
set [ find default-name=ether5 ] name=ether5-ap-beneden poe-out=forced-on
set [ find default-name=sfp1 ] disabled=yes
/interface ethernet switch port
set 0 vlan-mode=secure
set 1 default-vlan-id=50 vlan-mode=secure
set 2 default-vlan-id=50 vlan-mode=secure
set 3 default-vlan-id=50 vlan-mode=secure
set 4 vlan-mode=secure
set 5 vlan-mode=secure
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge-lan interface=ether1-trunk
add bridge=bridge-lan interface=ether2-tv
add bridge=bridge-lan interface=ether3-nuc
add bridge=bridge-lan interface=ether4-amp
add bridge=bridge-lan interface=ether5-ap-beneden
/ip neighbor discovery-settings
set discover-interface-list=all
/interface ethernet switch vlan
add independent-learning=no ports=ether1-trunk,ether2-tv,ether3-nuc,ether4-amp,ether5-ap-beneden switch=switch1 vlan-id=50
add independent-learning=no ports=ether1-trunk,ether5-ap-beneden switch=switch1 vlan-id=51
add independent-learning=yes ports=ether1-trunk,ether5-ap-beneden switch=switch1 vlan-id=1
Вопрос: На RB960PGS мне нужно добавить VLAN ID 1 (что логично) и включить independent-learning, чтобы управлять CAP. Это правильная настройка? Потому что на роутере я явно не использую VLAN ID 1.

