intro to vlans on the crs - mummum.mikrotik.com/presentations/us16/presentation_2937_1462452… ·...
TRANSCRIPT
![Page 1: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/1.jpg)
MUM 2016 CRS VLans
Intro To VLANS on the CRS
Joshua Gray, Brian Vargyas
Baltic Networks
1
![Page 2: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/2.jpg)
MUM 2016 CRS VLans
Joshua Biou Joshua Gray
u Network Engineer Since 2008
u Finishing masters degree in Network Engineering and Security at DePaul University.
u Ipv6, MTCNA, MTCRE, MTCWE, MTCINE, InfraGuard
2
![Page 3: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/3.jpg)
MUM 2016 CRS VLans
Brian Bio
As the owner of Baltic Networks and a former wireline and wireless ISP, I’m always looking for that next product or service that makes your job as a service provider easier and improves your bottom line. I started in telecommunications in 1986 and got involved with Mikrotik in 2003 deploying large scale hotpots in airports worldwide. I’m also a certified Mikrotik trainer.
3
![Page 4: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/4.jpg)
MUM 2016 CRS VLans
The Swiss Army knife of VLANs
u The CRS is not your grandfather’s switch
u A cornucopia of VLAN fun awaits you
(Vlan Tag Switching)
u Number one request we get on CRS devices
![Page 5: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/5.jpg)
MUM 2016 CRS VLans
Benefits of Using VLANSu Many switches connected together can create an issue
with scalability
u The larger the broadcast domain the more traffic that is consumed in just broadcast frames
u One might not want a broadcast to reach a certain port for security concerns
u VLANS allow a physical layer two network to be split into several virtually isolated networks
u QOS- Different VLANS can have different priorities.
5
![Page 6: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/6.jpg)
MUM 2016 CRS VLans
VLAN Planningu Ports can be put into a trunk mode or access level mode
u Broadcasts are sent only to ports that are participating in the VLAN
u Each VLAN should be a single subnet.
6
![Page 7: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/7.jpg)
MUM 2016 CRS VLans
Inter VLAN Routing?!?!u One can route between vlans using a router on a stick.
u Or using the CRS but keep in mind it is not extremely powerful.
7
![Page 8: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/8.jpg)
MUM 2016 CRS VLans
OSI Model
8
![Page 9: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/9.jpg)
MUM 2016 CRS VLans
Ethernet Frame
9
![Page 10: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/10.jpg)
MUM 2016 CRS VLans
Packet Capture
10
![Page 11: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/11.jpg)
MUM 2016 CRS VLans
Packet Capture
11
![Page 12: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/12.jpg)
MUM 2016 CRS VLans
Packet Capture
12
Trunk
Access LevelVLAN Tag
No VLAN Tag
![Page 13: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/13.jpg)
MUM 2016 CRS VLans
Trunk VS Accessu Trunks
u Links between switches
u Links to servers with multiple subnets
u Links to other network devices that support Vlans
u Admin systems that need access to multiple Vlans
u Access
u Links between end user devices
u Links to APs that only needs single VLAN
u Guest devices
13
![Page 14: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/14.jpg)
MUM 2016 CRS VLans
Setup
Trunk Office Guest
u One trunk back to core switches. (Eth1)
u Ports 3-6 trunked for multiple SSID on access points
u Ports 9-13 access ports for Office users (VLAN 11)
u Ports 17-20 access ports for Guest users (VLAN 21)
14
![Page 15: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/15.jpg)
MUM 2016 CRS VLans
Set up Switch Chipu Slave all all ports to Eth1
15
![Page 16: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/16.jpg)
MUM 2016 CRS VLans
Set up Switch Chipu Slave all all ports to Eth1
16
/interface ethernetset [ find default-name=ether2 ] master-port=ether1set [ find default-name=ether3 ] master-port=ether1set [ find default-name=ether4 ] master-port=ether1set [ find default-name=ether5 ] master-port=ether1set [ find default-name=ether6 ] master-port=ether1set [ find default-name=ether7 ] master-port=ether1set [ find default-name=ether8 ] master-port=ether1set [ find default-name=ether9 ] master-port=ether1set [ find default-name=ether10 ] master-port=ether1set [ find default-name=ether11 ] master-port=ether1set [ find default-name=ether12 ] master-port=ether1…
![Page 17: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/17.jpg)
MUM 2016 CRS VLans
Add Vlansu Switch > VLAN +
u Add Vlan 11
u Add Ports 1,2,3,4,5,6 (Will Be Trunk)
u Add Ports 9,10,11,12,13 (Will be Access Layer)
u These ports are for the office network.
17
![Page 18: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/18.jpg)
MUM 2016 CRS VLans
Add Vlansu Switch > VLAN +
u Add Vlan 21
u Add Ports 1,3,4,5,6 (Trunk ports)
u Add Ports17,18,19,20 (Will be Access Layer)
u These ports are for the office network.
18
![Page 19: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/19.jpg)
MUM 2016 CRS VLans
Add Vlans
19
/interface ethernet switch vlanadd ports=“ether1,ether2,ether3,ether4,ether5,ether6,\ether9,ether10,ether11,ether12,ether13” vlan-id=11
add ports=ether1,ether3,ether4,ether5,ether6,ether17,\ether18,ether19,ether20 vlan-id=21
u Switch > VLAN +
u Add Vlan 11
u Add Vlan 21
![Page 20: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/20.jpg)
MUM 2016 CRS VLans
Setup Trunk Portsu Switch > VLAN > Eg. VLAN TAG
20
![Page 21: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/21.jpg)
MUM 2016 CRS VLans
Setup Trunk Ports
21
u Switch > VLAN > Eg. VLAN TAG
/interface ethernet switch egress-vlan-tagadd tagged-ports=ether1,ether2,ether3,ether4,ether5,\ether6 vlan-id=21
add tagged-ports=ether1,ether2,ether3,ether4,ether5,\ether6 vlan-id=11
![Page 22: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/22.jpg)
MUM 2016 CRS VLans
Ingress Portsu Setup access level ports to tag traffic that comes in
appropriately.
u Switch > VLAN > In. VLAN TAG
u Service VID: Used for service provider tagging
u PCP: Used to set priority
u DEI: Drop eligibility indicator
22
![Page 23: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/23.jpg)
MUM 2016 CRS VLans
Ingress Ports
23
u Set access level ports for the office network
u Traffic inbound to the switch
u Ports 9, 10, 11,12, 13
![Page 24: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/24.jpg)
MUM 2016 CRS VLans
Ingress Ports
24
u Set access level ports for the Guest network
u Traffic inbound to the switch
u Ports 17,18,19,20
![Page 25: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/25.jpg)
MUM 2016 CRS VLans
Ingress Ports
25
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=11 ports=\ether9,ether10,ether11,ether12,ether13
add customer-vid=0 new-customer-vid=21 ports=ether17\,ether18,ether19,ether20
![Page 26: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/26.jpg)
MUM 2016 CRS VLans
Egressu Setup access level ports to tag traffic that comes in
appropriately.
u Switch > VLAN > Eg. VLAN TAG
26
![Page 27: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/27.jpg)
MUM 2016 CRS VLans
Egress
27
u Set access level ports for the Guest network
u Traffic outbound from the switch
u Ports 9, 10, 11,12, 13
![Page 28: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/28.jpg)
MUM 2016 CRS VLans
Egress
28
u Set access level ports for the Guest network
u Traffic inbound to the switch
u Ports 17,18,19,20
![Page 29: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/29.jpg)
MUM 2016 CRS VLans
Egress
29
/interface ethernet switch egress-vlan-translationadd customer-vid=11 customer-vlan-format=untagged-or-tagged\new-customer-vid=0 ports=ether9,ether10,ether11,ether12\,ether13 ports=untagged-or-tagged
add customer-vid=21 customer-vlan-format=untagged-or-tagged\new-customer-vid=0 ports=ether17,ether18,ether19,ether20\customer-vlan-format=untagged-or-tagged
![Page 30: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/30.jpg)
MUM 2016 CRS VLans
CRS IP on the VLAN? u Add switch chip to VLAN and Eg. VLAN Tag.
30
![Page 31: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/31.jpg)
MUM 2016 CRS VLans
CRS IP on the VLAN? u Create VLAN on Master Port.
31
![Page 32: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/32.jpg)
MUM 2016 CRS VLans
CRS IP on the VLAN? u Assign IP to that port.
32
![Page 33: Intro To VLANS on the CRS - MUMmum.mikrotik.com/presentations/US16/presentation_2937_1462452… · u Service VID: Used for service provider tagging u PCP: Used to set priority u DEI:](https://reader034.vdocuments.net/reader034/viewer/2022051910/5fff8d45e4333a616d4e358b/html5/thumbnails/33.jpg)
MUM 2016 CRS VLans
Questions?
33