I've set up some vlans which appear to all be functioning properly except for one thing: traffic is allowed to pass between them unhindered. Here's the config:
Gateway
Code: Select all
[user@MikroTik] > interface vlan print
Flags: X - disabled, R - running, S - slave
# NAME MTU ARP VLAN-ID INTERFACE
0 R vlan100 1500 enabled 100 ether6
1 R vlan200 1500 enabled 200 ether6
2 R vlan300 1500 enabled 300 ether6
[user@MikroTik] > ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
LAN
0 10.13.31.254/24 10.13.31.0 vlan100
1 10.13.32.254/24 10.13.32.0 vlan200
2 10.13.33.254/24 10.13.33.0 vlan300
DHCP server is configured to hand out the respective ranges.
Code: Select all
[user@MikroTik] > /interface vlan print
Flags: X - disabled, R - running, S - slave
# NAME MTU ARP VLAN-ID INTERFACE
0 R vlan100 1500 enabled 100 lan_bridge
1 R vlan200 1500 enabled 200 lan_bridge
2 R vlan300 1500 enabled 300 lan_bridge
[user@MikroTik] > /interface bridge port print
Flags: X - disabled, I - inactive, D - dynamic
# INTERFACE BRIDGE PRIORITY PATH-COST HORIZON
0 ether1 lan_bridge 0x80 10 none
1 I ether2 lan_bridge 0x80 10 none
2 I ether3 lan_bridge 0x80 10 none
3 I ether4 lan_bridge 0x80 10 none
4 I ether5 lan_bridge 0x80 10 none
5 vlan100 br-vlan1-Administ... 0x80 10 none
6 wlan1 br-vlan1-Administ... 0x80 10 none
7 vlan200 br-vlan2-Faculty 0x80 10 none
8 I wlan2 br-vlan2-Faculty 0x80 10 none
9 vlan300 br-vlan3-Guest 0x80 10 none
10 I wlan3 br-vlan3-Guest 0x80 10 none
[user@MikroTik] > interface wireless print
Flags: X - disabled, R - running
0 R ;;;Administration
name="wlan1" mtu=1500 mac-address=D4:CA:6D:21:2F:7A arp=enabled
interface-type=Atheros 11N mode=ap-bridge ssid="Administrative Access"
frequency=2412 band=2ghz-b/g/n channel-width=20mhz scan-list=default
wireless-protocol=802.11 antenna-mode=ant-a wds-mode=disabled
wds-default-bridge=none wds-ignore-ssid=no bridge-mode=enabled
default-authentication=yes default-forwarding=no default-ap-tx-limit=0
default-client-tx-limit=0 hide-ssid=yes
security-profile=Administration WPA compression=no
1 ;;;Faculty
name="wlan2" mtu=1500 mac-address=D6:CA:6D:21:2F:7B arp=enabled
interface-type=virtual-AP master-interface=wlan1 ssid="Faculty"
wds-mode=disabled wds-default-bridge=none wds-ignore-ssid=no
bridge-mode=enabled default-authentication=yes default-forwarding=no
default-ap-tx-limit=0 default-client-tx-limit=0 hide-ssid=no
security-profile=Faculty WPA
2 ;;;Guest
name="wlan3" mtu=1500 mac-address=D6:CA:6D:21:2F:7B arp=enabled
interface-type=virtual-AP master-interface=wlan1 ssid="Guest"
wds-mode=disabled wds-default-bridge=none wds-ignore-ssid=no
bridge-mode=enabled default-authentication=yes default-forwarding=no
default-ap-tx-limit=0 default-client-tx-limit=0 hide-ssid=no
For example, I can only ping 10.13.31.254 if I specify to use br-vlan1-Administration vlan. Once I change it to br-vlan2-Faculty, pings start timing out. Isolation appears to be happening up to the AP. I suspect that the problem has something to do with the wireless or bridge configuration.