...
Code Block |
---|
|
/interface ethernet switch vlan
add ports=ether2,ether3,ether4,ether5 switch=switch1 vlan-id=400200
add ports=ether2,ether3,ether4,ether5 switch=switch1 vlan-id=300
add ports=ether2,ether3,ether4,ether5 switch=switch1 vlan-id=200400 |
In switch port menu set vlan-mode
on all ports and also default-vlan-id
on planned hybrid ports:
Code Block |
---|
|
/interface ethernet switch port
set ether2 vlan-mode=secure vlan-header=leave-as-is
set ether3 vlan-mode=secure vlan-header=leave-as-is default-vlan-id=400200
set ether4 vlan-mode=secure vlan-header=leave-as-is default-vlan-id=300
set ether5 vlan-mode=secure vlan-header=leave-as-is default-vlan-id=200400 |
vlan-mode=secure
will ensure strict use of VLAN table.default-vlan-id
will define VLAN for untagged ingress traffic on port.- In QCA8337 and Atheros8327 chips when
vlan-mode=secure
is used, it ignores switch port vlan-header
options. VLAN table entries handle all the egress tagging/untagging and works as vlan-header=leave-as-is
on all ports. It means what comes in tagged, goes out tagged as well, only default-vlan-id
frames are untagged at the egress port.
...