I just bought a RB4011iGS appliance to use at work for a bit of a special case. This is an industrial manufacturing facility (but the router is in the nice clean server room)
We have a handful of VLANs on a air-gapped physical network. The VLANs do not talk to each other, and there is no routing between them currently.
We wanted to have a NTP server to help keep some of the RTCs aligned across various equipment and services (cameras, control systems, loggers, etc).
We have installed a GPS based timeclock system for the most critical VLAN, and it is working great. However, we would now like to offer the time syncing function across all the VLANs.
Enter RB4011iGS. I would like to use it's 8 ports to service the various VLANs (through untagged ports/cables) for the purpose of NTP only. I do not want any routing functions.
I simply want the mikrotik device to grab the time, and then handle requests from the devices on each individual VLAN.
I have just spent an hour cruising around the WebUI trying to figure it out, and I'm in way over my head.
It looks like i need to assign an IP to each interface (IP in each VLAN's subnet), and then enable the NTP Client (to grab time from my GPS unit) and the NTP Server (to serve time up each port/VLAN via the Port's IP). We want to block all communications between the VLANs to maintain the isolation.
Could anyone point me to the simplest way to disable the routing/switching functions between the ports, and still maintain the ability to access the webUI?
My only other experience with routing was with a pfSense install at home and it starts up with routing disabled (or no rules to allow it anyway).