VLAN转发:
VLAN标记:VLAN模式、VLAN头、VLAN表都可以用于VLAN标记
端口镜像配置实例:
/interface ethernet switch
set switch1 mirror-source=ether2 mirror-target=ether3
[admin@MikroTik] /interface ethernet switch> print
Flags: I - invalid
# NAME TYPE MIRROR-SOURCE MIRROR-TARGET SWITCH-ALL-PORTS
0 switch1 Realtek-RTL8367 ether2 ether3
1 switch2 Realtek-RTL8367 none none
2 switch3 Realtek-RTL8367 none none
主机表:
主机表:表示交换芯片内部的MAC地址到端口的映射
属性:动态静态两种,接收到某个数据包时它将数据包的源mac地址X和接收到该数据包的端口添加到主机表中
端口隔离:
菜单:/interface ethernet switch port-isolation
专用VLAN配置实例:
专用VLAN:将所有流量转发到上行端口,并将所有端口进行隔离
端口隔离配置:
/interface bridge
add name=bridge1
/interface bridge port
add interface=sfp1 bridge=bridge1 hw=yes
add interface=ether1 bridge=bridge1 hw=yes
add interface=ether2 bridge=bridge1 hw=yes
add interface=ether3 bridge=bridge1 hw=yes
覆盖需要隔离的每个交换机端口的出口端口(上行链路端口除外)
/interface ethernet switch port-isolation
set ether1 forwarding-override=sfp1
set ether2 forwarding-override=sfp1
set ether3 forwarding-override=sfp1
隔离交换组实例:
切换所有端口:
/interface bridge
add name=bridge
/interface bridge port
add bridge=bridge1 interface=ether1 hw=yes
add bridge=bridge1 interface=ether2 hw=yes
add bridge=bridge1 interface=ether3 hw=yes
add bridge=bridge1 interface=ether4 hw=yes
add bridge=bridge1 interface=ether5 hw=yes
add bridge=bridge1 interface=ether6 hw=yes
add bridge=bridge1 interface=ether7 hw=yes
add bridge=bridge1 interface=ether8 hw=yes
创建隔离组接口
/interface ethernet switch port-isolation
set ether1 forwarding-override=ether2,ether3,ether4
set ether2 forwarding-override=ether1,ether3,ether4
set ether3 forwarding-override=ether1,ether2,ether4
set ether4 forwarding-override=ether1,ether2,ether3
为B组创建隔离组
/interface ethernet switch port-isolation
set ether5 forwarding-override=ether6,ether7,ether8
set ether6 forwarding-override=ether5,ether7,ether8
set ether7 forwarding