Code: Select all
/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
Running 6.12? Post your export. Reset your configuration to defaults and test it.Hi, CRS-125 works as a hub, sending all packets to all ports. Command that recommend to apply does not work on the latest firmware.
This command does not work. Recommend any hack? Please.Code: Select all/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
Yes, 6.12. Any problems are solved by resetting the Mikrotik? Every time? Device in other city ~6000 km. I have only remote access...Running 6.12? Post your export. Reset your configuration to defaults and test it.Hi, CRS-125 works as a hub, sending all packets to all ports. Command that recommend to apply does not work on the latest firmware.
This command does not work. Recommend any hack? Please.Code: Select all/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
[ivn@yakut1-gtw01] /interface ethernet switch port> print
Flags: I - invalid
0 name="ISP1" egress-customer-tpid=0x8100 egress-service-tpid=0x88A8 learn=no allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=30 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all
allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none
qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no
pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
1 name="ISP2" egress-customer-tpid=0x8100 egress-service-tpid=0x88A8 learn=no allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=30 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all
allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none
qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no
pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
2 name="ether03-master" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port
allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none
ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no
pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
3 name="ether04-slave" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port
allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none
ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no
pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
4 name="ether05-slave" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port
allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none
ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no
pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
Post your actual export. Not a print.Yes, 6.12. Any problems are solved by resetting the Mikrotik? Every time? Device in other city ~6000 km. I have only remote access...Running 6.12? Post your export. Reset your configuration to defaults and test it.Hi, CRS-125 works as a hub, sending all packets to all ports. Command that recommend to apply does not work on the latest firmware.
This command does not work. Recommend any hack? Please.Code: Select all/interface ethernet switch port set [find] learn-restricted-unknown-sa=yes
Code: Select all[ivn@yakut1-gtw01] /interface ethernet switch port> print Flags: I - invalid 0 name="ISP1" egress-customer-tpid=0x8100 egress-service-tpid=0x88A8 learn=no allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=30 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes="" 1 name="ISP2" egress-customer-tpid=0x8100 egress-service-tpid=0x88A8 learn=no allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=30 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes="" 2 name="ether03-master" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes="" 3 name="ether04-slave" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes="" 4 name="ether05-slave" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=no pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
I do not fully understand invalid vlan filtering, I tried to follow the example but it differs we do not have intervlan routing and do not desire to have it in the switch either.You, probably, need to configure invalid VLAN filtering to block broadcasts from unwanted VLANs.
Sample configuration is in the last section of this CRS example:
http://wiki.mikrotik.com/wiki/Manual:CR ... _filtering
Okey, I got support from my Mikrotik vendor, he says, basically use example "InterVLAN Routing with unknown VLAN filtering":I do not fully understand invalid vlan filtering, I tried to follow the example but it differs we do not have intervlan routing and do not desire to have it in the switch either.You, probably, need to configure invalid VLAN filtering to block broadcasts from unwanted VLANs.
Sample configuration is in the last section of this CRS example:
http://wiki.mikrotik.com/wiki/Manual:CR ... _filtering
That configuration did not work at all, if I connect a server to the switch it becomes fully unavailable.
Can you please come up with a "normal switch with vlan and trunks example connected to cisco/hp trunk" or something similar.
The tip from vendor did not work at all, the device now hangs forever starting services, device is bricked.....Okey, I got support from my Mikrotik vendor, he says, basically use example "InterVLAN Routing with unknown VLAN filtering":I do not fully understand invalid vlan filtering, I tried to follow the example but it differs we do not have intervlan routing and do not desire to have it in the switch either.You, probably, need to configure invalid VLAN filtering to block broadcasts from unwanted VLANs.
Sample configuration is in the last section of this CRS example:
http://wiki.mikrotik.com/wiki/Manual:CR ... _filtering
That configuration did not work at all, if I connect a server to the switch it becomes fully unavailable.
Can you please come up with a "normal switch with vlan and trunks example connected to cisco/hp trunk" or something similar.
1. Slave against ether1 not ether2!
2. Then you must connect your management vlans to switch1-cpu
3. Then you must put the switch admin ip address on vlan(s), if you want to be able reaching it.
I will test this and come back with the result within the neares days.
If all then work, CRS has start become very useful.
We finally got it working in LAB, thanks to MT support: http://forum.mikrotik.com/viewtopic.php?f=3&t=78797 see bottom of link.Hello Folks!
Tested ROS6.13 today (full reset without defaults and updated it, no netinstall yet).
The same CRS port based vlans and inter vlan routing examples same results all fail, no traffic at all is passed through the device to any ports, and yes we tried using both ether1 and ether2 as master port.
Positive is that CRS does not hang anymore, and it was not bricket a reset helped out.
If it works, with some other settings, then I start to feel we do not have that deep competence to deal with ingress/outgress tagging and policy groups I have seen people discussing here and there but never saw anyone coming up with some working results that I could understand, so maybe CRS as a switch is not for us after all. It has also started to consume lot of time doing all those tests when a new RoS is rolled out.
However, the device is usful as a plain switch, without using any vlans and such stuff, and we do use some for that here since months back.
We did never try using it as a router due to it's weak CPU, it might work in some small SOHO network which yet has not got 100Mbit/s internet.
Absolutely, I put in all the steps because I have had so much struggles with it that I dont know if it will work if leaving one of the steps below out. So I am sorry, it will be relaitively much text, hopefully it helps you out.Could you please post the solution?
On the link you gave are a lot of configurations, a lot of tests, but where is the solution to the problem described?
Something like: do this command and that command and it's done. If possible without decorations of any kind...