Přidat otázku mezi oblíbenéZasílat nové odpovědi e-mailem 2x MikroTik hAP lite a VLAN

To jsem udělal, teď mám tuto konfiguraci :

/interface bridge
add fast-forward=no name=Bridge_HOST
add fast-forward=no name=Bridge_LAN
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN
set [ find default-name=ether2 ] name=ether2-LAN
set [ find default-name=ether3 ] name=ether3-LAN
set [ find default-name=ether4 ] name=ether4-TRUNK
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n mode=ap-bridge name=wlan1-LAN \
    ssid=MikroTik wps-mode=disabled
/interface vlan
add interface=ether4-TRUNK name=vlan-host vlan-id=20
add interface=ether4-TRUNK name=vlan-lan vlan-id=10
/interface wireless
add disabled=no keepalive-frames=disabled mac-address=6E:3B:6B:31:F7:44 \
    master-interface=wlan1-LAN multicast-buffering=disabled name=wlan1-HOST \
    ssid=xxx_HOST wds-cost-range=0 wds-default-cost=0 wps-mode=disabled
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=pool_LAN ranges=10.0.0.10-10.0.0.254
add name=pool_HOST ranges=10.10.10.10-10.10.10.254
/ip dhcp-server
add address-pool=pool_LAN disabled=no interface=Bridge_LAN lease-time=1d name=\
    DHCP_LAN
add address-pool=pool_HOST disabled=no interface=Bridge_HOST lease-time=1d \
    name=DHCP_HOST
/interface bridge port
add bridge=Bridge_LAN interface=wlan1-LAN
add bridge=Bridge_LAN interface=ether2-LAN
add bridge=Bridge_LAN interface=ether3-LAN
add bridge=Bridge_LAN interface=vlan-lan
add bridge=Bridge_HOST interface=vlan-host
add bridge=Bridge_HOST interface=wlan1-HOST
/ip neighbor discovery-settings
set discover-interface-list=all
/ip address
add address=10.0.0.1/24 interface=Bridge_LAN network=10.0.0.0
add address=10.10.10.1/24 interface=Bridge_HOST network=10.10.10.0
/ip dhcp-client
add disabled=no interface=ether1-WAN
/ip dhcp-server config
set store-leases-disk=never
/ip dhcp-server network
add address=10.0.0.0/24 gateway=10.0.0.1
add address=10.10.10.0/24 gateway=10.10.10.1
/ip firewall filter
add action=drop chain=forward dst-address=10.10.10.0/24 src-address=10.0.0.0/24
add action=drop chain=forward dst-address=10.0.0.0/24 src-address=10.10.10.0/24
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-WAN
/ipv6 dhcp-client
add add-default-route=yes interface=ether1-WAN pool-name=ipv6 request=prefix
/system clock
set time-zone-name=Europe/Prague
/system routerboard settings
set silent-boot=no
[admin@MikroTik] > 

Je to OK? Momentálně jsem zkoušel dát na eth4 starší AirCa8-PRO, co umí VLANy a z 10.10.10.0/24 se dostanu do 10.0.0.0/24 i přes Firewall.

Reakce na odpověď

1 Zadajte svou přezdívku:
2 Napište svou odpověď:
3 Pokud chcete dostat ban, zadejte libovolný text:

Zpět do poradny