Code: Select all
# port with pvid added to untagged group which might cause problems, consider adding a seperate VLAN entry
But I have no untagged ports, only a single trunk port on the bridge. Even the dynamically added wlan ports become tagged on the bridge because of CAPs. This is very confusing.Can someone shed some light on what's wrong? The configuration is working as intended but the warning bugs me.
The full config:
Code: Select all
# jun/29/2021 23:14:56 by RouterOS 6.47.9
# software id = x
#
# model = RBcAPGi-5acD2nD
# serial number = x
/interface bridge
add frame-types=admit-only-vlan-tagged ingress-filtering=yes name=br-trunk \
protocol-mode=none pvid=2 vlan-filtering=yes
/interface wireless
# managed by CAPsMAN
# channel: 2452/20-Ce/gn(18dBm), SSID: benedict, local forwarding
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
disabled=no distance=indoors frequency=auto installation=indoor mode=\
ap-bridge ssid=MikroTik-5CB1F0 wireless-protocol=802.11
# managed by CAPsMAN
# channel: 5640/20-eeCe/ac/DP(24dBm), SSID: benedict, local forwarding
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-XXXX disabled=no distance=indoors frequency=auto \
installation=indoor mode=ap-bridge ssid=MikroTik-5CB1F1 \
wireless-protocol=802.11
/interface ethernet
set [ find default-name=ether2 ] disabled=yes
/interface vlan
add interface=br-trunk name=vlan2-mgmt vlan-id=2
add interface=br-trunk name=vlan10-lan vlan-id=10
add interface=br-trunk name=vlan20-guest vlan-id=20
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/interface bridge port
add bridge=br-trunk frame-types=admit-only-vlan-tagged ingress-filtering=yes \
interface=ether1 pvid=2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface bridge vlan
# port with pvid added to untagged group which might cause problems, consider adding a seperate VLAN entry
add bridge=br-trunk tagged=ether1,br-trunk vlan-ids=2,10,20
/interface list member
add comment=defconf list=LAN
add comment=defconf interface=ether1 list=WAN
/interface wireless cap
#
set bridge=br-trunk certificate=request discovery-interfaces=vlan2-mgmt \
enabled=yes interfaces=wlan1,wlan2
/ip address
add address=192.168.88.12/24 interface=vlan2-mgmt network=192.168.88.0
/ip dhcp-client
add comment=defconf disabled=no
/ip dns
set servers=192.168.88.1
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip route
add distance=1 gateway=192.168.88.1
/system clock
set time-zone-name=Europe/x
/system identity
set name=ap2.bnh.hu
/system ntp client
set enabled=yes primary-ntp=192.168.88.1
/system routerboard mode-button
set enabled=yes on-event=dark-mode
/system script
add comment=defconf dont-require-permissions=no name=dark-mode owner=*sys \
policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
source="\r\
\n :if ([system leds settings get all-leds-off] = \"never\") do={\r\
\n /system leds settings set all-leds-off=immediate \r\
\n } else={\r\
\n /system leds settings set all-leds-off=never \r\
\n }\r\
\n "
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN