Is it easy for a noob to setup things like port forwarding and vlans on a router/ap box?
Is it easy for a noob to setup things like port forwarding and vlans on a router/ap box?
On the other hand, I'm not sure "unintuitive" is the correct word here. Having had the (dis)pleasure of setting up complex topologies on other manufactures like Cisco I found MikroTik to be considerably more intuitive (or perhaps "less unintuitive" would be more appropriate), possibly because Cisco has been built on for many decades and new features were constantly added on top of existing systems for compatibility purposes instead of redoing the CLI from scratch to make a more consistent user experience.
Anyone posting on HN will likely be able to figure out the basics, but it is definitely much less polished than other prosumer products such as Ubiquiti and the documentation can be a little rough around the edges.
Having said that - if you know network setup very well, then Mikrotiks are very powerful and allow for network setups that are much more flexible than consumer equipment.
(Also configuring IPv6 correctly is also a special hell that's far away from clicking "enable IPv6" on my previous ASUS)
The criticism on their firewall might as well be a criticism on iptables (which IMO is completely valid, even after years I still have doubts about what a certain rules structure is going to do).
iptables itself is extremely unintuitive (although extremely powerful and flexible), but their GUI makes it more manageable.
I've managed cisco amd juniper routers. And I can't make heads nor tails of it.
As soon as you wonder off the default track, you're expected to understand deep level networking terminology abstracted in a UI tailored for experts.
Mikrotik's SwOS is alright and has most of the options you'd expect from a switch, but is missing the ability to have a human readable text config. I've got a Netgear switch as well, and I'd label its obtuseness on par with RouterOS. At the end of the day it seems every network vendor has their own bespoke proprietary UI that you have to suffer through.
In general I'm much more at home with Linux's iproute2/bridge-utils/nft. What I really want is some low power switches that can run OpenFlow or the like so I can centralize all the config back to my Linux router. On a home network, most devices shouldn't be talking directly among themselves anyway!
Another thing I really want is for network switches to have an RGB LED on each port that can indicate what VLAN it's configured for.
If you want to set ether 3, 4 and 5 to untagged vlan called "Alf" with ID 11, ether 6 to untablled vlan "Bob" (id 12), and ether 7 and 8 to a trunk of both Alf and Bob, you can do
1) Create a bridge for Alf, and a bridge for Bob
2) Assign IPs for them (assuming your mikrotik is the router), and maybe dhcp pools, server etc
3) add ether3, 4 and 5 as bridge ports for Alf, and ether6 for Bob
4) Create a vlan interface on ether7 for Alf with vlanid=11, add to bridge Alf
5) Create a vlan interface on ether8 for Alf with vlanid=11, add to bridge Alf
6) Create a vlan interface on ether7 for Bob with vlanid=21, add to bridge Bob
7) Create a vlan interface on ether8 for Bob with vlanid=21, add to bridge Bob
But the killer is there are two different recommended ways to do it depending on the hardware.
/interface bridge port
add bridge=_bridge interface=sfp-sfpplus1
add bridge=_bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=sfp2 pvid=10
But then I also have to define the VLAN ID for the bridge (for egress, I believe) - /interface bridge vlan
add bridge=_bridge tagged=sfp-sfpplus1,_bridge, untagged=sfp2 vlan-ids=10
The device is a CRS328-4C-20S-4S+RM. It seems like I am using the other recommended way. Which would make sense because I'm not really using the "router" part of the software, but rather configuring the built in switch chip to do its thing.Looking at the text config now it seems quite sensible, and isn't far from SwOS, Linux CLI, or switch chip datasheets. But I remember getting to that point in the WebUI being somewhat confusing, perhaps due to the alternative in-CPU way you described.
- you need to enable hardware offloading for it
- different models have different limits on number of hardware offloaded bridges
- if it's not hardware offloaded, you run all traffic through cpu and kill throughput
When compared to consumer router devices, then no.
When compared to configuring enterprise networking kit using the CLI ... well ... perhaps. Mikrotik does have some short cuts / UI features. But if you want to do anything vaguely complex, you're going to need to put some serious time into getting your head around the way the system processes packets.
If getting to grips with how packets flow through different subsystems in your router doesn't really appeal (check out https://wiki.mikrotik.com/wiki/Manual:Packet_Flow) then there are better, simpler options which are still powerful.
you can go on fiverr and upwork and get someone to remotely configure/manage it for you.
I'm not quite sure what you mean here. Everyone from banks to small shops use IT configuration services.
Most people will supply you a resume, contact details and sign a NDA. That's quite good enough.
everything more or less maps directly onto raw Linux functionality