What's new

Need some assistance on VLANs on a Mikrotik RB2011 router

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

djgizmo

Occasional Visitor
The RB2011 router does have two switch chips. I mainly just use mine a home lab / soho router.

However my wife is starting to work from home more and more, and I'd like to segment her specific port from the rest and prevent other subnets from being able to communicate with one another.

I'm green when it comes to VLANs, and I'd like to think I catch on quick, but I'm kinda lost how to best approach this.

Suggestions?


Sent from my iPhone using Tapatalk
 
Its simple, you can create 2 switched networks that arent connected to each other than you'll need to do 2 NAT rules for both switches/ports.

You can use VLANs (port to wife pc with a number and other ports get other numbers while the port that connects them to internet will be a member of both VLANs. I believe mikrotik uses a different terminology for their VLANs.

You can use L3 segmentation meaning use of different IP subnets which would require more complicated rules (you can define 2 IP subnets in the same firewall rule like forward - source 192.168.1.0/24,192.168.2.0/24 destination- !192.168.1.0/24,!192.168.2.0/24 as an example)

The ! for LAN address in destination is very important if you want to prevent accidently NATing local traffic.
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top