Fri Nov 24, 2023 5:54 pm
I am looking at a somewhat similar setup and have some problems that I can't really figure out.
I'm using a CSS326-24G-2S for my setup, which also has two SFP+ ports and the rest are 1Gig only.
I am running pfsense as my firwall/router and normally plug the fiber module directly into that machine. However, now I wanted to play around with some other firewalls, which I can run virtualized on a different server in the same rack. And instead of having to move the fiber module every time I switch between machines, I thought of using the Mikrotik as a glorified media converter.
I have already tried this on TP-Link switch, whiched worked perfectly fine.
What I do is to set up the SFP+ and another of the ports with VLAN 500, and nothing more. As they are the only ports in the switch which accept that TAG, it simply creates a "tunnel" between the two ports. This "tunnel" can of course go across switches, provided the VLAN 500 is part of the trunk. Which I suppose is the scenario Jojoljobar is after...
And now I wanted to use the Mikrotik for this exact same purpose as the TP-Link, but I can't get it to work out!
I have tried using only port isolation, modifying the mapping so that only the two ports I want to, can talk to each other.
I have tried setting up separate VLAN for the two ports only.
I have tried combining port isolation and VLAN.
I have tried without VLAN entirely (only having a VLAN for the port I use for accessing the UI).
I have been fiddling with other settings like IGMP snooping, Fast Leave, Discovery Protocol etc. but it doesn't seem to matter.
Whichever way I try, I lose my IP on pfsense after some 6-7 hours or so. Which makes it a slow process when testing...
Mikrotik reports both ports Link UP, and I can even see traffic on pfsense, but no IP and hence no Internet. I can pcap WAN from within pfsense and see a lot of "traffic" hitting the port, basically revealing a lot of MAC's on the ISP side, but I don't really know if there's anything there which could reveal what's going on?.
The second I plug the module back directly into pfsense, I get my IP back. When I do change over to go via the Mikrotik switch, it takes a long time before pfsense picks up the IP, more than a minute I belive. Whereas when I do the same thing in the TP-Link case, I get an IP in an instant.
What can be different between the switches, and what can possibly be going on with the Mikrotik switch in this scenario??