i am struggling for 2 days how to proceed with my provider settings and Mikrotik. My ISP provided me dlink router DIR-2150 on this router i specify/enable igmpv2 and interface for IP TV (untagged) and WAN tagged with vlan 388 and it is working fine. I replaced this router with Mikrotik but nothing works for me expect internet....configured 2 Bridges 1 VLAN1 - all devices except isp tv decoder, and second bridge vlan388 and iptv doesn't work, I tried all settings not tv doesn't even started


我现在的配置:
Code:Select all
# 7月/ 02/2023 09:14:56 Roul雷竞技terOS 6.49.8 # software id = **ELIDED** # # model = RB760iGS # serial number = **ELIDED** /interface bridge add name=Bridge_VLAN1 add arp=proxy-arp igmp-snooping=yes multicast-querier=yes name=Bridge_VLAN388 /interface ethernet set [ find default-name=ether4 ] name=Dekoder_TV set [ find default-name=ether1 ] mac-address=A8:63:7D:9C:AA:B6 name=WAN_Internet set [ find default-name=ether3 ] name=Wifi_Router set [ find default-name=sfp1 ] mac-address=A8:63:7D:9C:AA:B6 /interface vlan add interface=WAN_Internet name=VLAN1 vlan-id=1 add interface=WAN_Internet name=VLAN388 vlan-id=388 /interface ethernet switch port set 3 default-vlan-id=388 /interface list add comment=defconf name=WAN add comment=defconf name=LAN /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /ip pool add name=dhcp ranges=192.168.88.10-192.168.88.254 add name=dhcp_pool1 ranges=192.168.88.2-192.168.88.254 add name=dhcp_pool2 ranges=192.168.90.2-192.168.90.254 add name=dhcp_pool3 ranges=192.168.88.2-192.168.88.254 add name=dhcp_pool4 ranges=192.168.0.2-192.168.0.254 /ip dhcp-server add address-pool=dhcp disabled=no interface=Bridge_VLAN1 name=dhcp2 add address-pool=dhcp_pool4 disabled=no interface=Bridge_VLAN388 name=dhcp1 /interface bridge port add bridge=Bridge_VLAN1 interface=ether2 add bridge=Bridge_VLAN1 interface=Wifi_Router add bridge=Bridge_VLAN1 interface=ether5 add bridge=Bridge_VLAN388 frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes \ interface=Dekoder_TV pvid=388 add bridge=Bridge_VLAN388 disabled=yes interface=WAN_Internet pvid=388 /ip neighbor discovery-settings set discover-interface-list=LAN /interface bridge vlan add bridge=Bridge_VLAN388 tagged=Bridge_VLAN388,WAN_Internet untagged=Dekoder_TV vlan-ids=388 add bridge=Bridge_VLAN1 untagged=Wifi_Router,ether2,ether5 vlan-ids=1 /interface detect-internet set detect-interface-list=all internet-interface-list=WAN lan-interface-list=LAN wan-interface-list=\ WAN /interface list member add comment=defconf interface=ether5 list=LAN add interface=ether2 list=LAN add interface=WAN_Internet list=WAN /ip address add address=192.168.88.1/24 interface=Bridge_VLAN1 network=192.168.88.0 add address=192.168.0.1/24 interface=Bridge_VLAN388 network=192.168.0.0 /ip dhcp-client add disabled=no interface=WAN_Internet /ip dhcp-server network add address=0.0.0.0/24 comment=defconf gateway=0.0.0.0 netmask=24 add address=192.168.0.0/24 gateway=192.168.0.1 add address=192.168.88.0/24 gateway=192.168.88.1 netmask=24 /ip dns set allow-remote-requests=yes /ip dns static add address=192.168.88.1 comment=defconf name=router.lan /ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" \ connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=\ 127.0.0.1 add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=\ established,related add action=accept chain=forward comment="defconf: accept established,related, untracked" \ connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \ connection-nat-state=!dstnat connection-state=new in-interface-list=WAN add action=accept chain=forward protocol=udp add action=accept chain=input protocol=udp add action=accept chain=forward protocol=igmp add action=accept chain=input protocol=igmp add action=accept chain=forward dst-address=239.239.0.0/16 add action=accept chain=input dst-address=239.239.0.0/16 add action=accept chain=input dst-address=224.0.0.0/4 add action=accept chain=forward dst-address=224.0.0.0/4 /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none \ out-interface-list=WAN add action=masquerade chain=srcnat out-interface-list=WAN add action=masquerade chain=srcnat out-interface=VLAN388 /routing igmp-proxy set quick-leave=yes /routing igmp-proxy interface add alternative-subnets=0.0.0.0/0 interface=WAN_Internet upstream=yes add interface=Bridge_VLAN388 /system clock set time-zone-name=Europe/Warsaw /system identity set name=MikrotikRouterSzafa /tool mac-server set allowed-interface-list=LAN /tool mac-server mac-winbox set allowed-interface-list=LAN /tool sniffer set file-name=test.pcap streaming-enabled=yes streaming-server=192.168.0.136