Sat Jul 24, 2021 10:11 pm
Here is my MicroTik configuration so far, all input is appreciated.
/interface bridge
add name=bridge-dmz vlan-filtering=yes
add name=bridge-guest vlan-filtering=yes
add name=bridge-inside vlan-filtering=yes
add name=bridge-management vlan-filtering=yes
add name=bridge-storage vlan-filtering=yes
add name=bridge-vmotion vlan-filtering=yes
/interface ethernet
set [ find default-name=sfp-sfpplus1 ] name=ethernet1
set [ find default-name=sfp-sfpplus2 ] name=ethernet2
set [ find default-name=sfp-sfpplus3 ] name=ethernet3
set [ find default-name=sfp-sfpplus4 ] name=ethernet4
set [ find default-name=sfp-sfpplus5 ] name=ethernet5
set [ find default-name=sfp-sfpplus6 ] name=ethernet6
set [ find default-name=sfp-sfpplus7 ] name=ethernet7
set [ find default-name=sfp-sfpplus8 ] name=ethernet8
set [ find default-name=sfp-sfpplus9 ] name=ethernet9
set [ find default-name=sfp-sfpplus10 ] name=ethernet10
set [ find default-name=sfp-sfpplus11 ] name=ethernet11
set [ find default-name=sfp-sfpplus12 ] name=ethernet12
set [ find default-name=sfp-sfpplus13 ] name=ethernet13
set [ find default-name=sfp-sfpplus14 ] name=ethernet14
set [ find default-name=sfp-sfpplus15 ] name=ethernet15
set [ find default-name=sfp-sfpplus16 ] name=ethernet16
set [ find default-name=ether1 ] name=mgmt0
/interface vlan
add name=vlan-client vlan-id=120
add name=vlan-dmz vlan-id=250
add name=vlan-guest vlan-id=200
add name=vlan-management vlan-id=100
add name=vlan-server vlan-id=110
add name=vlan-storage vlan-id=500
add name=vlan-transit vlan-id=998
add name=vlan-vmotion vlan-id=600
/interface bonding
add mode=802.3ad name=port-channel10 slaves=ethernet1,ethernet2 transmit-hash-policy=layer-2-and-3
add mode=802.3ad name=port-channel20 slaves=ethernet3,ethernet4 transmit-hash-policy=layer-2-and-3
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add interface=port-channel10 pvid=500
add interface=port-channel20 pvid=110
add interface=mgmt0
add interface=ethernet5
add interface=ethernet6
add interface=ethernet7
add interface=ethernet8
add interface=ethernet9
add interface=ethernet10
add interface=ethernet11
add interface=ethernet12
add interface=ethernet13
add interface=ethernet14
add interface=ethernet15
add interface=ethernet16 pvid=120
/interface bridge vlan
add bridge=bridge-management tagged=bridge-management,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 vlan-ids=100
add bridge=bridge-inside tagged=bridge-inside,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 untagged=port-channel20 \
vlan-ids=110
add bridge=bridge-inside tagged=bridge-inside,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 untagged=ethernet16 vlan-ids=\
120
add bridge=bridge-guest tagged=bridge-guest,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 vlan-ids=200
add bridge=bridge-dmz tagged=bridge-dmz,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 vlan-ids=250
add bridge=bridge-storage tagged=bridge-storage,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 untagged=port-channel10 \
vlan-ids=500
add bridge=bridge-vmotion tagged=bridge-vmotion,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 vlan-ids=600
add bridge=bridge-inside tagged=bridge-inside,mgmt0,ethernet5,ethernet6,ethernet9,ethernet10 vlan-ids=998
/ip address
add address=172.22.100.3/24 interface=vlan-management network=172.22.100.0
add address=172.22.110.1/24 interface=vlan-server network=172.22.110.0
add address=172.22.120.1/24 interface=vlan-client network=172.22.120.0
add address=172.22.200.1/24 interface=vlan-guest network=172.22.200.0
add address=172.22.250.1/24 interface=vlan-dmz network=172.22.250.0
add address=172.22.255.2/24 interface=vlan-transit network=172.22.255.0
add address=172.22.50.1/24 interface=vlan-storage network=172.22.50.0
add address=172.22.60.1/24 interface=vlan-vmotion network=172.22.60.0
/ip route
add distance=1 gateway=172.22.100.4 routing-mark=vrf-management
add distance=1 gateway=172.22.255.4 routing-mark=vrf-inside
add distance=1 gateway=172.22.200.4 routing-mark=vrf-guest
add distance=1 gateway=172.22.250.4 routing-mark=vrf-dmz
/ip route vrf
add interfaces=bridge-management route-distinguisher=100:100 routing-mark=vrf-management
add interfaces=bridge-inside route-distinguisher=110:110 routing-mark=vrf-inside
add interfaces=bridge-guest route-distinguisher=200:200 routing-mark=vrf-guest
add interfaces=bridge-dmz route-distinguisher=250:250 routing-mark=vrf-dmz
add interfaces=bridge-storage route-distinguisher=500:500 routing-mark=vrf-storage
add interfaces=bridge-vmotion route-distinguisher=600:600 routing-mark=vrf-vmotion
Kind Regards,
Lars Christian Thasenhod
Last edited by
lthasenhod on Sun Jul 25, 2021 6:59 pm, edited 1 time in total.