Community discussions

MikroTik App
 
DanielD
just joined
Topic Author
Posts: 2
Joined: Sat Jun 17, 2023 6:27 pm

Rechable only for SNMP

Sat Jun 17, 2023 6:38 pm

Hi,

I have a CRS318-16P-2S+OUT setup. It will be "only" used to assign VLANs for the Ethernet Port, the uplink is via a 10G connection.

The issue I'm encountering is the device can be queried by SNMP (correctly) but is not reachable via SSH, WEB, Ping or WinBox, ...



Configuration:
# 2023-06-17 15:32:18 by RouterOS 7.10
# software id = T3P6-SIYQ
#
# model = CRS318-16P-2S+
/interface bridge
add ingress-filtering=no name=CORP protocol-mode=none vlan-filtering=yes
/interface ethernet
set [ find default-name=sfp-sfpplus1 ] name=Uplink
set [ find default-name=ether1 ] poe-lldp-enabled=yes poe-priority=8
set [ find default-name=ether2 ] poe-lldp-enabled=yes poe-priority=1
set [ find default-name=ether3 ] poe-lldp-enabled=yes poe-priority=4
set [ find default-name=ether4 ] poe-lldp-enabled=yes poe-priority=5
set [ find default-name=ether5 ] poe-lldp-enabled=yes poe-priority=6
set [ find default-name=ether6 ] poe-lldp-enabled=yes poe-priority=7
set [ find default-name=ether7 ] poe-lldp-enabled=yes poe-priority=2
set [ find default-name=ether8 ] poe-lldp-enabled=yes poe-priority=3
set [ find default-name=ether9 ] poe-lldp-enabled=yes poe-priority=1
set [ find default-name=ether10 ] poe-lldp-enabled=yes poe-priority=2
set [ find default-name=ether11 ] poe-lldp-enabled=yes poe-priority=5
set [ find default-name=ether12 ] poe-lldp-enabled=yes poe-priority=6
set [ find default-name=ether13 ] poe-lldp-enabled=yes poe-priority=7
set [ find default-name=ether14 ] poe-lldp-enabled=yes poe-priority=8
set [ find default-name=ether15 ] poe-lldp-enabled=yes poe-priority=3
set [ find default-name=ether16 ] poe-lldp-enabled=yes poe-priority=4
/interface vlan
add interface=CORP name=Network-Mgmt vlan-id=100
/interface ethernet switch
set 0 name=SWITCH
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/port
set 0 name=serial0
/snmp community
set [ find default=yes ] name=IhaveaCommunity
/interface bridge port
add bridge=CORP interface=ether1 pvid=16
add bridge=CORP interface=ether2 pvid=16
add bridge=CORP interface=ether3 pvid=16
add bridge=CORP interface=ether4 pvid=16
add bridge=CORP interface=ether5 pvid=16
add bridge=CORP interface=ether6 pvid=16
add bridge=CORP interface=ether7 pvid=16
add bridge=CORP interface=ether8 pvid=16
add bridge=CORP interface=ether9 pvid=16
add bridge=CORP interface=ether10 pvid=16
add bridge=CORP interface=ether11 pvid=16
add bridge=CORP interface=ether12 pvid=16
add bridge=CORP interface=ether13 pvid=16
add bridge=CORP interface=ether14 pvid=16
add bridge=CORP frame-types=admit-only-vlan-tagged interface=Uplink pvid=99
add bridge=CORP interface=sfp-sfpplus2
/ip neighbor discovery-settings
set discover-interface-list=all
/ipv6 settings
set disable-ipv6=yes forward=no
/interface bridge vlan
add bridge=CORP tagged=Uplink vlan-ids=100
add bridge=CORP tagged=Uplink vlan-ids=8
add bridge=CORP tagged=Uplink vlan-ids=12
add bridge=CORP tagged=Uplink untagged="ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14" vlan-ids=16
add bridge=CORP tagged=Uplink vlan-ids=32
add bridge=CORP tagged=Uplink vlan-ids=48
add bridge=CORP tagged=Uplink vlan-ids=68
add bridge=CORP tagged=Uplink vlan-ids=72
add bridge=CORP tagged=Uplink vlan-ids=80
add bridge=CORP tagged=Uplink vlan-ids=244
add bridge=CORP tagged=Uplink vlan-ids=3999
add bridge=CORP tagged=Uplink vlan-ids=64
add bridge=CORP tagged=Uplink vlan-ids=77
/ip address
add address=10.100.76.214/24 interface=Network-Mgmt network=10.100.76.0
/ip route
add distance=1 gateway=10.100.76.1
/radius
add address=10.16.4.5 service=login
/snmp
set contact="CORP" enabled=yes location=TOWN
/system identity
set name=CORP
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system routerboard settings
set boot-os=router-os
/user aaa
set accounting=no default-group=full use-radius=yes
 
drasked
just joined
Posts: 11
Joined: Sun Jun 18, 2023 1:03 pm

Re: Rechable only for SNMP

Sun Jun 18, 2023 1:46 pm

This might do the trick;

/interface bridge vlan
add bridge=CORP tagged=Uplink,CORP untagged=Network-Mgmt vlan-ids=100
 
wiseroute
Member
Member
Posts: 425
Joined: Sun Feb 05, 2023 11:06 am

Re: Rechable only for SNMP

Sun Jun 18, 2023 5:31 pm

hello

looks like a simple question - but actually not 😂

have a CRS318-16P-2S+OUT setup. It will be "only" used to assign VLANs for the Ethernet Port, the uplink is via a 10G connection.
I'm sorry i don't get your question.

do you mean the switch just basically for vlan access with 1 vlan trunk port?

issue I'm encountering is the device can be queried by SNMP (correctly) but is not reachable via SSH, WEB, Ping or WinBox, ...
did you put those services on the correct vlan?
have you set allowed ips to connect from?
 
DanielD
just joined
Topic Author
Posts: 2
Joined: Sat Jun 17, 2023 6:27 pm

Re: Rechable only for SNMP

Sun Jun 18, 2023 9:05 pm

Hello,
do you mean the switch just basically for vlan access with 1 vlan trunk port?
The Ports 1-16 ar access ports with one VLAN where the SFP+ Port is a trunk port with multiple VLANs
did you put those services on the correct vlan?
have you set allowed ips to connect from?
Yes I assume so because I can query the device remotely via SNMP.
have you set allowed ips to connect from?
No I have not configured any allowed or disallowed IPs