MikroTik — Configurare porte ACCESS e TRUNK (riferimento) Guida generica per configurare le porte di un bridge VLAN-aware come access (una VLAN, per un PC) o trunk (più VLAN taggate, per un apparato VLAN-aware). Sostituisci i placeholder: etherX, etherY = porte da configurare etherUP = uplink verso lo switch a monte (es. ether1) = un ID VLAN (es. 9, 173) , = più ID VLAN Presuppone bridge in vlan-filtering=yes. 1. Access vs Trunk — il concetto ACCESS TRUNK VLAN sulla porta una sola più di una Tag untagged (senza tag) tagged (col tag) Cosa colleghi un PC / dispositivo normale switch, router, AP (VLAN-aware) PVID = la VLAN della porta 1 (neutro) Le tre primitive: tagged = la VLAN esce/entra col tag → trunk untagged = la VLAN esce/entra senza tag → access PVID = a quale VLAN assegnare il traffico untagged in ingresso ⚠️ Sicurezza: se metti una porta access sulla VLAN di management, chi si collega lì raggiunge SSH/WinBox del router. Comodo come "porta di rientro" fidata, ma non esporla a utenti non affidabili. 2. Porta ACCESS Un PC su etherX finisce nella VLAN senza saperlo. Creare (VLAN nuova) /interface bridge vlan add bridge=bridge vlan-ids= tagged=etherUP untagged=etherX /interface bridge port set [find interface=etherX] pvid= tagged=etherUP → la VLAN arriva taggata dallo switch a monte. untagged=etherX → esce pulita verso il PC. pvid= → il traffico del PC entra nella VLAN giusta. Aggiungere una porta access a una VLAN che ESISTE già La VLAN c'è già in tabella → modifica (non add), aggiungendo la porta agli untagged: /interface bridge vlan set [find vlan-ids=] tagged=etherUP untagged=etherX /interface bridge port set [find interface=etherX] pvid= set riscrive l'intera lista: rielenca i tagged/untagged già presenti che devono restare. Convertire una porta da TRUNK ad ACCESS Se la porta era tagged e la vuoi untagged: /interface bridge vlan set [find vlan-ids=] tagged=etherUP untagged=etherX /interface bridge port set [find interface=etherX] pvid= (togli etherX dai tagged rielencando solo le porte da mantenere, e mettila negli untagged) 3. Porta TRUNK Su etherX colleghi un apparato VLAN-aware. Più VLAN taggate. Creare # aggiungere la porta al bridge /interface bridge port add bridge=bridge interface=etherX # una VLAN /interface bridge vlan add bridge=bridge vlan-ids= tagged=etherUP,etherX # più VLAN nella stessa riga /interface bridge vlan add bridge=bridge vlan-ids=, tagged=etherUP,etherX # PVID neutro (di solito già 1) /interface bridge port set [find interface=etherX] pvid=1 Aggiungere una porta a una VLAN già esistente /interface bridge vlan set [find vlan-ids=] tagged=etherUP,etherX ⚠️ set tagged=... sovrascrive: rielenca tutte le porte da mantenere. Native VLAN (una VLAN untagged sul trunk) /interface bridge vlan set [find vlan-ids=] tagged=etherUP untagged=etherX /interface bridge port set [find interface=etherX] pvid= 4. Togliere / modificare # togliere una VLAN SOLO da una porta (riscrivi senza quella porta) /interface bridge vlan set [find vlan-ids=] tagged=etherUP # rimuovere una VLAN da TUTTE le porte /interface bridge vlan remove [find vlan-ids=] # togliere la porta dal bridge del tutto /interface bridge port remove [find interface=etherX] # cambiare il PVID /interface bridge port set [find interface=etherX] pvid=1 Disabilitare (granularità) Obiettivo Comando VLAN off su tutto lo switch /interface bridge vlan disable [find vlan-ids=] VLAN off solo su una porta non c'è disable per-porta: usa set togliendo la porta 5. Verifica /interface bridge vlan print detail # config reale (tagged/untagged) /interface bridge port print # PVID, flag hw-offload (H), inactive (I) /interface bridge host print where interface=etherX # MAC appresi sulla porta /interface bridge host print where interface=etherX vid= tagged vs current-tagged: tagged = configurato (sempre); current-tagged = attivo ora (solo porte up). Porta scollegata ( I) → non appare in current-tagged ma la config c'è: guarda print detail. Filtri host: i campi sono interface e vid, NON on-interface/ vlan-id. Dopo where premi Tab per l'elenco dei campi validi. 6. Lato switch a monte (Cisco) Ogni VLAN usata sul MikroTik deve essere allowed anche sul trunk dell'apparato a monte: vlan vlan interface switchport mode trunk switchport trunk allowed vlan add , 7. Trappole comuni (imparate sul campo) set tagged=... / untagged=... SOVRASCRIVE la lista intera — rielenca sempre le porte da mantenere, o le perdi. add di una VLAN che esiste già → failure: vlan already added, e fallisce l'INTERO comando (anche le altre VLAN della stessa riga). Se una VLAN esiste (es. la management), aggiungi la porta con set, non con add. Access = untagged + PVID. Servono entrambi: senza PVID il traffico in ingresso dal PC finisce in VLAN 1. Trunk = tagged + PVID 1. Il PVID resta neutro perché tutto viaggia taggato. VLAN di management: modificandola, mantieni sempre tagged=bridge,etherUP o perdi l'accesso. Lavora in Safe Mode ( Ctrl+X). Config su entrambi i lati: la VLAN va permessa sia sul MikroTik sia sull'apparato a monte. Porta scollegata ( I): verifica con print detail, non col riepilogo. 8. Chiusura (quando funziona) [Ctrl+X] # esci da Safe Mode = rende permanente /system backup save name=porte-vlan-ok /export file=config-porte-vlan Scarica i file dal menu Files e conservali fuori dal router.