Troubles with MAC based VLAN on CRS-125
Posted: Thu Dec 08, 2016 12:54 am
CRS-125 is an internet NAT gateway providing internet access to clients segmented via MAC based VLANs. Unfortunately, I can't figure out what's missing. I followed the tutorial in the wiki for MAC based VLANs.
ether1-cfg = configuration port with static IP for setup
ether2-wan = DHCP client for WAN
ether3-lan = master port for all other LAN ports and VLANs
Client 00:11:22:33:44:55 cannot even ping the 10.10.8.1 interface on vlan80 and obviously internet access is not working. Any ideas?
/interface ethernet
set [ find default-name=ether1 ] name=ether1-cfg
set [ find default-name=ether2 ] name=ether2-wan
set [ find default-name=ether3 ] name=ether3-lan
set [ find default-name=ether4 ] master-port=ether3-lan
set [ find default-name=ether5 ] master-port=ether3-lan
set [ find default-name=ether6 ] master-port=ether3-lan
set [ find default-name=ether7 ] master-port=ether3-lan
set [ find default-name=ether8 ] master-port=ether3-lan
set [ find default-name=ether9 ] master-port=ether3-lan
set [ find default-name=ether10 ] master-port=ether3-lan
set [ find default-name=ether11 ] master-port=ether3-lan
set [ find default-name=ether12 ] master-port=ether3-lan
set [ find default-name=ether13 ] master-port=ether3-lan
set [ find default-name=ether14 ] master-port=ether3-lan
set [ find default-name=ether15 ] master-port=ether3-lan
set [ find default-name=ether16 ] master-port=ether3-lan
set [ find default-name=ether17 ] master-port=ether3-lan
set [ find default-name=ether18 ] master-port=ether3-lan
set [ find default-name=ether19 ] master-port=ether3-lan
set [ find default-name=ether20 ] master-port=ether3-lan
set [ find default-name=ether21 ] master-port=ether3-lan
set [ find default-name=ether22 ] master-port=ether3-lan
set [ find default-name=ether23 ] master-port=ether3-lan
set [ find default-name=ether24 ] master-port=ether3-lan
/interface vlan
add interface=ether3-lan name=vlan70 vlan-id=70
add interface=ether3-lan name=vlan80 vlan-id=80
/interface ethernet switch egress-vlan-tag
add tagged-ports=ether3-lan vlan-id=80
add tagged-ports=ether3-lan vlan-id=70
/interface ethernet switch mac-based-vlan
add new-customer-vid=80 src-mac-address=00:11:22:33:44:55
/interface ethernet switch port
set 2 allow-fdb-based-vlan-translate=yes allow-mac-based-customer-vlan-assignment-for=untagged-and-priority-tagged-frame-only
/interface ethernet switch vlan
add ports=ether3-lan vlan-id=80
add ports=ether3-lan vlan-id=70
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether1-cfg network=192.168.88.0
add address=10.10.8.1/24 interface=vlan80 network=10.10.8.0
add address=10.10.7.1/24 interface=vlan70 network=10.10.7.0
add address=10.10.0.1/24 interface=ether3-lan network=10.10.0.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether2-wan
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether2-wan
/system clock
set time-zone-name=America/New_York
/system routerboard settings
set protected-routerboot=disabled
ether1-cfg = configuration port with static IP for setup
ether2-wan = DHCP client for WAN
ether3-lan = master port for all other LAN ports and VLANs
Client 00:11:22:33:44:55 cannot even ping the 10.10.8.1 interface on vlan80 and obviously internet access is not working. Any ideas?
/interface ethernet
set [ find default-name=ether1 ] name=ether1-cfg
set [ find default-name=ether2 ] name=ether2-wan
set [ find default-name=ether3 ] name=ether3-lan
set [ find default-name=ether4 ] master-port=ether3-lan
set [ find default-name=ether5 ] master-port=ether3-lan
set [ find default-name=ether6 ] master-port=ether3-lan
set [ find default-name=ether7 ] master-port=ether3-lan
set [ find default-name=ether8 ] master-port=ether3-lan
set [ find default-name=ether9 ] master-port=ether3-lan
set [ find default-name=ether10 ] master-port=ether3-lan
set [ find default-name=ether11 ] master-port=ether3-lan
set [ find default-name=ether12 ] master-port=ether3-lan
set [ find default-name=ether13 ] master-port=ether3-lan
set [ find default-name=ether14 ] master-port=ether3-lan
set [ find default-name=ether15 ] master-port=ether3-lan
set [ find default-name=ether16 ] master-port=ether3-lan
set [ find default-name=ether17 ] master-port=ether3-lan
set [ find default-name=ether18 ] master-port=ether3-lan
set [ find default-name=ether19 ] master-port=ether3-lan
set [ find default-name=ether20 ] master-port=ether3-lan
set [ find default-name=ether21 ] master-port=ether3-lan
set [ find default-name=ether22 ] master-port=ether3-lan
set [ find default-name=ether23 ] master-port=ether3-lan
set [ find default-name=ether24 ] master-port=ether3-lan
/interface vlan
add interface=ether3-lan name=vlan70 vlan-id=70
add interface=ether3-lan name=vlan80 vlan-id=80
/interface ethernet switch egress-vlan-tag
add tagged-ports=ether3-lan vlan-id=80
add tagged-ports=ether3-lan vlan-id=70
/interface ethernet switch mac-based-vlan
add new-customer-vid=80 src-mac-address=00:11:22:33:44:55
/interface ethernet switch port
set 2 allow-fdb-based-vlan-translate=yes allow-mac-based-customer-vlan-assignment-for=untagged-and-priority-tagged-frame-only
/interface ethernet switch vlan
add ports=ether3-lan vlan-id=80
add ports=ether3-lan vlan-id=70
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether1-cfg network=192.168.88.0
add address=10.10.8.1/24 interface=vlan80 network=10.10.8.0
add address=10.10.7.1/24 interface=vlan70 network=10.10.7.0
add address=10.10.0.1/24 interface=ether3-lan network=10.10.0.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether2-wan
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether2-wan
/system clock
set time-zone-name=America/New_York
/system routerboard settings
set protected-routerboot=disabled