I have the RB4011 Router worrking! It was the
datapath.bridge. It now has a main and a guest wifi and various access ports on various vlans.
I am now stuck trying to get the RB2011 working as an AP.
I am trying to have:
- the main SSID athome on vlan 64
- the guest SSID athome_guest on vlan 66
The RB2011 AP is connected to the RB4011 Router on ether9.
I suspect I have got the following incorrect
- ether9 on the RB4011 setting incorrect - I suspect I don't have it as a Trunk
- the Bridge VLAN entries on the RB2011 AP
It would be great if someone could help me get this last bit right.
RB2011 AP Config
# 2024-12-04 21:45:50 by RouterOS 7.16.1
# software id = 65FW-3KRA
#
# model = RB2011UiAS-2HnD
/interface bridge add admin-mac=4C:5E:0C:B8:9D:91 auto-mac=no comment=defconf name=bridgeLocal protocol-mode=none vlan-filtering=yes
/interface ethernet set [ find default-name=ether10 ] name="ether10 - OffBridge"
/interface wifi security add authentication-types=wpa2-psk,wpa3-psk disabled=no name=sec_athome
/interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik
/interface wireless security-profiles add authentication-types=wpa2-psk mode=dynamic-keys name=sec_athome supplicant-identity=""
/interface wireless security-profiles add authentication-types=wpa2-psk mode=dynamic-keys name=sec_athome_guest supplicant-identity=""
/interface wireless set [ find default-name=wlan1 ] band=2ghz-onlyn country="united kingdom" disabled=no frequency=auto installation=indoor mode=ap-bridge security-profile=sec_athome ssid=athome5 wps-mode=disabled
/interface wireless add disabled=no keepalive-frames=disabled mac-address=4E:5E:0C:B8:9D:9B master-interface=wlan1 multicast-buffering=disabled name=wlan2 security-profile=sec_athome_guest ssid=athome_guest2 wds-cost-range=0 wds-default-cost=1 wps-mode=disabled
/port set 0 name=serial0
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether1
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether2 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether3 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether4 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether5 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether6 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether7 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether8 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf interface=ether9 pvid=64
/interface bridge port add bridge=bridgeLocal comment=defconf disabled=yes interface=sfp1
/interface bridge port add bridge=bridgeLocal interface=wlan1 pvid=64
/interface bridge port add bridge=bridgeLocal interface=wlan2 pvid=66
/interface bridge vlan add bridge=bridgeLocal tagged=ether1,bridgeLocal vlan-ids=64
/interface bridge vlan add bridge=bridgeLocal tagged=ether1 vlan-ids=66
/interface wifi cap set discovery-interfaces=bridgeLocal
/interface wireless access-list add comment=Breeze interface=wlan1 mac-address=74:38:B7:0C:AF:1B vlan-mode=no-tag
/interface wireless access-list add comment=PingPi2 interface=wlan1 mac-address=B8:27:EB:20:F7:7E vlan-mode=no-tag
/interface wireless access-list add comment=Pixel-9 interface=wlan1 mac-address=C0:1C:6A:70:FE:1F vlan-mode=no-tag
/interface wireless cap set bridge=bridgeLocal discovery-interfaces=bridgeLocal interfaces=wlan1
/ip address add address=192.168.78.1/30 interface="ether10 - OffBridge" network=192.168.78.0
/ip dhcp-client add comment=defconf interface=bridgeLocal
/lcd interface pages set 0 interfaces="sfp1,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10 - OffBridge"
/system clock set time-zone-name=Europe/London
/system identity set name="RB2011 64.3"
/system note set show-at-login=no
RB4011 Router Config
# 2024-12-04 22:06:18 by RouterOS 7.16.1
# software id = YCNI-BQ6N
#
# model = RB4011iGS+5HacQ2HnD
/interface bridge add admin-mac=C4:AD:34:60:79:47 auto-mac=no comment=bridge name=bridge protocol-mode=none vlan-filtering=yes
/interface ethernet set [ find default-name=ether1 ] comment="ether1 - Internet" name="ether1 - Internet" rx-flow-control=auto tx-flow-control=auto
/interface ethernet set [ find default-name=ether2 ] comment="ether2 - OffBridge2" name="ether2 - OffBridge2"
/interface ethernet set [ find default-name=ether3 ] comment="ether3 " name="ether3 "
/interface ethernet set [ find default-name=ether4 ] comment="ether4 " name="ether4"
/interface ethernet set [ find default-name=ether5 ] comment=ether5
/interface ethernet set [ find default-name=ether6 ] comment="ether6 " name="ether6"
/interface ethernet set [ find default-name=ether7 ] comment="ether7 " name="ether7"
/interface ethernet set [ find default-name=ether8 ] comment="ether8" name="ether8"
/interface ethernet set [ find default-name=ether9 ] comment="ether9 - UpUp Router MK3" name="ether9 - UpUp Router MK3"
/interface ethernet set [ find default-name=ether10 ] comment="ether1 " name="ether10" poe-out=forced-on
/interface ethernet set [ find default-name=sfp-sfpplus1 ] disabled=yes
/interface wireguard add comment="Wireguard General Interface" listen-port= mtu=1420 name=WireGuard
/interface vlan add comment=vlan64 interface=bridge name=vlan64 vlan-id=64
/interface vlan add interface=bridge name=vlan66 vlan-id=66
/interface vlan add interface=bridge name=vlan68 vlan-id=68
/interface list add comment=defconf name=WAN
/interface list add comment=defconf name=LAN
/interface list add name=TRUSTED
/interface list add name=MAIN
/interface wifi security add authentication-types=wpa2-psk,wpa3-psk disabled=no name=sec_athome
/interface wifi security add authentication-types=wpa2-psk,wpa3-psk disabled=no name=sec_guest
/interface wifi set [ find default-name=wifi1 ] channel.band=5ghz-ac .skip-dfs-channels=10min-cac .width=20/40mhz-eC comment="5ghz Wifi - athome" configuration.country="United Kingdom" .manager=local .mode=ap .ssid=athome disabled=no name=wifi_athome security=sec_athome
/interface wifi add configuration.mode=ap .ssid=athome_guest disabled=no mac-address=C6:AD:34:60:79:51 master-interface=wifi_athome name=Guest_Wifi security=sec_guest security.authentication-types="" .ft=no .ft-preserve-vlanid=no
/interface wifi configuration add disabled=no manager=local name=cfg_guest security=sec_guest ssid=athome_g
/ip pool add name=pool_64 ranges=192.168.64.100-192.168.64.254
/ip pool add name=pool_68 ranges=192.168.68.2-192.168.68.254
/ip pool add name=pool_66 ranges=192.168.66.2-192.168.66.254
/ip dhcp-server add address-pool=pool_64 interface=vlan64 lease-time=10m name=dhcp_vlan64
/ip dhcp-server add address-pool=pool_68 interface=vlan68 lease-time=10m name=dhcp_vlan68
/ip dhcp-server add address-pool=pool_66 interface=vlan66 lease-time=10m name=dhcp_vlan66
/port set 0 name=serial0
/port set 1 name=serial1
/disk settings set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether3 - Cat Flap" pvid=68
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether4 - Alarm" pvid=68
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=ether5 pvid=64
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether6 - Sitting Room Router MK4" pvid=64
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether7 - Front Room" pvid=64
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether8 - DS218" pvid=64
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether9 - UpUp Router MK3" pvid=64
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface="ether10 - Up Router MK2" pvid=64
/interface bridge port add bridge=bridge comment=defconf disabled=yes interface=sfp-sfpplus1
/interface bridge port add bridge=bridge comment=defconf frame-types=admit-only-untagged-and-priority-tagged interface=wifi_athome pvid=64
/interface bridge port add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=Guest_Wifi pvid=66
/ip neighbor discovery-settings set discover-interface-list=LAN
/ipv6 settings set disable-ipv6=yes
/interface bridge vlan add bridge=bridge tagged=bridge vlan-ids=64
/interface bridge vlan add bridge=bridge tagged=bridge vlan-ids=68
/interface bridge vlan add bridge=bridge tagged=bridge untagged=Guest_Wifi vlan-ids=66
/interface list member add comment=defconf interface=bridge list=LAN
/interface list member add comment=defconf interface="ether1 - Internet" list=WAN
/interface list member add interface=WireGuard list=LAN
/interface list member add interface=vlan64 list=LAN
/interface list member add interface="ether2 - OffBridge2" list=LAN
/interface list member add interface="ether2 - OffBridge2" list=TRUSTED
/interface list member add interface=vlan68 list=LAN
/interface list member add interface=vlan66 list=LAN
/interface list member add interface=WireGuard list=MAIN
/interface list member add interface=vlan64 list=MAIN
/interface list member add interface="ether2 - OffBridge2" list=MAIN
ip address add address=192.168.64.1/24 comment="Main Network" interface=vlan64 network=192.168.64.0
/ip address add address=10.200.0.1/24 comment=RoadWarriors interface=WireGuard network=10.200.0.0
/ip address add address=10.100.0.1/24 comment=Mittens interface=WireGuard network=10.100.0.0
/ip address add address=10.64.0.1/24 comment=France interface=WireGuard network=10.64.0.0
/ip address add address=192.168.77.1/30 comment="Addresses on ether2 to allow free access to the Router. In case I mess up changes." interface="ether2 - OffBridge2" network=192.168.77.0
/ip address add address=192.168.68.1/24 comment="Machine Network" interface=vlan68 network=192.168.68.0
/ip address add address=192.168.66.1/24 comment="Guest Network" interface=vlan66 network=192.168.66.0
/ip dhcp-client add comment=defconf interface="ether1 - Internet" use-peer-dns=no
/ip dhcp-server network add address=192.168.64.0/24 comment=network_64 dns-server=192.168.64.1 gateway=192.168.64.1
/ip dhcp-server network add address=192.168.66.0/24 comment=network_66 dns-server=192.168.64.1 gateway=192.168.66.1
/ip dhcp-server network add address=192.168.68.0/24 comment=network_68 dns-server=192.168.64.1 gateway=192.168.68.1
/ip dns set allow-remote-requests=yes servers=9.9.9.9,149.112.112.112
/ip dns static add address=192.168.64.1 comment=defconf name=router.lan type=A
/ip firewall address-list add address=192.168.64.1-192.168.64.99 list=AllowToRouter
/ip firewall address-list add address=192.168.65.1-192.168.65.99 list=AllowToRouter
/ip firewall address-list add address=10.200.0.0/24 list=AllowToRouter
/ip firewall address-list add address=192.168.77.2 list=AllowToRouter
/ip firewall address-list add address=192.168.68.0/24 list=AllowToRouter
/ip firewall address-list add address=192.168.64.86 comment="Road Camera" list=Cameras
/ip firewall address-list add address=192.168.64.105 comment="Doorbell Camera" list=Cameras
/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ip firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=accept chain=input comment=Wireguard dst-port=13233 protocol=udp
/ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" disabled=yes log=yes protocol=icmp
/ip firewall filter add action=accept chain=input comment="Allow interfaces on TRUSTED list to access Router" in-interface-list=TRUSTED
/ip firewall filter add action=accept chain=input comment="Allow LAN UDP - DNS (53) NTP (123)" dst-port=53,123 in-interface-list=LAN protocol=udp
/ip firewall filter add action=accept chain=input comment="Allow LAN UDP - Netbios (137) DHCP (67) MK Discovery (5678)" disabled=yes dst-port=67,137,5678 in-interface-list=LAN protocol=udp
/ip firewall filter add action=accept chain=input comment="Allow LAN TCP - DNS (53)" dst-port=53 in-interface-list=LAN protocol=tcp
/ip firewall filter add action=accept chain=input comment="defconf: Allowed to Router (HTML, SSH, Winbox)" dst-port=80,22,8291 in-interface-list=!WAN protocol=tcp src-address-list=AllowToRouter
/ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
/ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
/ip firewall filter add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
/ip firewall filter add action=accept chain=forward comment="New from Trusted Main network to internet" connection-state=new in-interface-list=MAIN out-interface-list=WAN
/ip firewall filter add action=accept chain=forward comment="New from Trusted Main network to internal places" connection-state=new in-interface-list=MAIN out-interface-list=MAIN
/ip firewall filter add action=accept chain=forward comment="Guests can only get to the internet" connection-state=new in-interface=vlan66 out-interface-list=WAN
/ip firewall filter add action=accept chain=forward connection-state=new in-interface=vlan68 out-interface-list=WAN
/ip firewall filter add action=accept chain=forward comment="new Allow Cameras to get to DS218" connection-state=new dst-address=192.168.64.6 src-address-list=Cameras
/ip firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall filter add action=drop chain=input comment="Drop all else & Log"
/ip firewall filter add action=drop chain=forward log=yes log-prefix="Last Fwd:"
/ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
/ip route add comment=FranceLondon disabled=no distance=1 dst-address=192.168.65.0/24 gateway=10.64.0.3 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10
/ip route add comment=FranceSFRRouter disabled=no distance=1 dst-address=192.168.1.0/24 gateway=10.64.0.3 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10
/ip route add comment="To SFR Dongle" disabled=no distance=1 dst-address=192.168.9.0/24 gateway=10.64.0.3 pref-src=0.0.0.0 routing-table=main scope=30 suppress-hw-offload=no target-scope=10
/ip service set telnet disabled=yes
/ip service set ftp disabled=yes
/ip service set api disabled=yes
/ip service set api-ssl disabled=yes
/ip ssh set always-allow-password-login=yes
/ipv6 firewall address-list add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
/ipv6 firewall address-list add address=::1/128 comment="defconf: lo" list=bad_ipv6
/ipv6 firewall address-list add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
/ipv6 firewall address-list add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
/ipv6 firewall address-list add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
/ipv6 firewall address-list add address=100::/64 comment="defconf: discard only " list=bad_ipv6
/ipv6 firewall address-list add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
/ipv6 firewall address-list add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
/ipv6 firewall address-list add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ipv6 firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept UDP traceroute" dst-port=33434-33534 protocol=udp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
/ipv6 firewall filter add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
/ipv6 firewall filter add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
/ipv6 firewall filter add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept HIP" protocol=139
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
/ipv6 firewall filter add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
/ipv6 firewall filter add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/system clock set time-zone-name=Europe/London
/system identity set name=RB4011
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN