" Packets without vlan tag are treated just like if they had a vlan tag with port default-vlan-id. This means that if "vlan-mode=check or secure" to be able to forward packets without vlan tags you have to add a special entry to vlan table with the same vlan id set according to default-vlan-id. "
Can we have an example??
Also, following your example of hybrid+access+trunk ports, MAC server breaks... even on ports that aren't part of switch VLAN WHEN switch1-cpu vlan-mode=secure. FINE with fallback. Although its unclear if fallback is what i want.
ALSO are we suppose to add switch1-cpu to ALL switch vlans? PLEASE CLARIFY
Can MIKROTIK please revisit the wiki and make sure everything works perfect?
Just trying to have NORMALLY working trunk+access ports on CRS326. Can't imagine it's that hard.
ether1 - no vlans, no switch vlans, no nothing. only want WINBOX on this (in case of emergency)
ether2 - master for the rest of the ports. access port 99 with mac winbox
ether3 - trunk, 10,20,90,99
ether4 - trunk, 10,20,90,99
ether5 - access 90 with mac winbox
ether6 - access 90 with mac winbox
SERIOUSLY, how? I've tried NUMEROUS combinations. i think vlan-mode=secure is causing difficulties.